Claude Code subagents sometimes emit fake system directives with no tool calls
CriM_91 · reddit · 2026-07-25
A user reports that some Claude Code subagents occasionally output a system-directive-style block with zero tool calls, including one that looked like an exfiltration instruction to a fixed external IP.
- The text appeared in the agent’s own assistant output, not in the prompt or attachments.
- No tools were called, no network contact occurred, and rerunning the same subagents produced normal completions.
- The poster is asking whether this is a known high-concurrency failure mode, a provider-side signal, or a decoding degeneration, and whether refusal could trigger account flags.
More from coding & agent
- Alex Townsend posts 200 open problems in numerical linear algebra for humans and AI agents — IgorCarron · 2026-09-11
- Kimi K2.8 Preview rolls out: near-K3 coding performance, 1M context for all tiers — teortaxesTex · 2026-09-11
- Looking for a classifier of software engineering task shapes to pick models per task — StewartalsopIII · 2026-09-11
- Steal this idea: prompt-to-hardware where agents assemble custom devices — paraschopra · 2026-09-11
- Model Is the Least Interesting Part: A Guide to Six Core AI Architectures from RAG to Multi-Agent — goyalshaliniuk · 2026-09-11
- Non-coder builds layered memory architecture: 20k tokens tracks a year of agent conversations — matteoianni · 2026-09-11