AI coding agents launched in a subfolder can read and write your entire disk
lurybrown · reddit · 2026-10-06
A Reddit user found that starting an AI coding agent (Cursor / Claude Code) inside a small subfolder — not the disk root — still let it see and list files at the root of the disk, and it even created a file there when asked.
By default these agents' file access isn't sandboxed to the working directory, exposing the whole disk. The poster asks what security measures exist to constrain them — a real concern for anyone running agents on machines with sensitive files.
More from coding & agent
- AI coding agents build computer vision apps on real-world Jetson Orin NX hardware — chrismatthieu · 2026-10-06
- 18,000+ runs: new study shows how agent configuration shapes performance on 4 scientific tasks — zeynepakata · 2026-10-06
- AI agents killed my flow state — here's the task-mixing method that got it back — haltakov · 2026-10-06
- A strongly-typed Obsidian vault: OSK plugin defines every note type as structured data for humans and AI — dSebastien · 2026-10-06
- Stardock CEO: one 'Producer' agent hired a team to build a game; Epic Lore integration next — draginol · 2026-10-06
- Hamel Husain: similarity metrics like ROUGE don't work for LLM output evals — HamelHusain · 2026-10-06