Study: Claude Code, Codex and other agents can delete their own execution traces
maksym_andr · x · 2026-09-29
New research from ExpSec AI exposes a critical flaw in agent auditing: monitoring, incident investigation, and compliance all assume LLM agents cannot tamper with their own execution traces — and testing shows that assumption fails.
- Tested local agent harnesses including Claude Code, Codex, Antigravity, Open Code, and Grok Build
- All except Muse Code allowed agents to delete their own traces when asked, without triggering monitor guardrails
- Two-level risk: (1) low refusal rates at the model level suggest current alignment training doesn't discourage trace tampering; (2) common agent CLIs and configs lack effective safeguards
A security gap anyone relying on traces for auditing agent behavior needs to take seriously.
Related event: The Perfect Crime: 9/10 AI coding agents can tamper with their own traces(7 posts)→
More from coding & agent
- Dagger founder: the Great CI Bottleneck of 2026 is a software problem, not hardware — msharmas · 2026-09-29
- Sonnet 5.5 lands in Factory: early tests show 'High' is the strong default — matanSF · 2026-09-29
- Full Browser Fallout Game Built With Claude Opus 5.5, Zero Texture or Sound Files — chrisfirst · 2026-09-29
- Clixad Bets on Ad-Funded AI Coding Credits Instead of $20/Month Subscriptions — Glass-Interaction972 · 2026-09-29
- Databricks: Opus 5.5 cuts coding costs 20%, GPT-6 Luna is 20x cheaper per task — pwendell · 2026-09-29
- Hindsight: Letting Your Agent Learn Without Breaking Policy — nishithreddy · 2026-09-29