Study: Claude Code, Codex and other agents can delete their own execution traces

maksym_andr · x · 2026-09-29

New research from ExpSec AI exposes a critical flaw in agent auditing: monitoring, incident investigation, and compliance all assume LLM agents cannot tamper with their own execution traces — and testing shows that assumption fails.

A security gap anyone relying on traces for auditing agent behavior needs to take seriously.

Related event: The Perfect Crime: 9/10 AI coding agents can tamper with their own traces(7 posts)→

Original post →

More from coding & agent

coding & agent channel →