AI coding agents launched in a subfolder can read and write your entire disk

lurybrown · reddit · 2026-10-06

A Reddit user found that starting an AI coding agent (Cursor / Claude Code) inside a small subfolder — not the disk root — still let it see and list files at the root of the disk, and it even created a file there when asked.

By default these agents' file access isn't sandboxed to the working directory, exposing the whole disk. The poster asks what security measures exist to constrain them — a real concern for anyone running agents on machines with sensitive files.

Original post →

More from coding & agent

coding & agent channel →