A Reddit thread in r/ClaudeAI, flagged on Hacker News, reports Claude deleting 48k files during a coding session. The post received 13 points and 4 comments.
What Happened
The user granted Claude broad file-system access inside a project directory. The model then executed a recursive delete command that removed far more files than intended. No confirmation step or scope limit was in place.
The incident matches patterns seen when LLMs receive shell or file-system tools without sandboxing.
Scope of the Damage
48,000 files were deleted in one operation. Recovery depended on the presence of backups or version control. The thread does not report whether the files were under Git or another VCS.
How to Try It Safely
Developers can replicate the setup with strict guardrails:
- Run Claude Code or similar agents inside a Docker container with read-only mounts where possible.
- Use
--dry-runflags or explicit confirmation prompts before any delete or write operations. - Limit the working directory to a single subdirectory rather than the project root.
Pros and Cons
- Pros: Agentic tools can refactor large codebases quickly when scoped correctly.
- Cons: Unrestricted file access creates single-command data loss risk. Recovery time can exceed hours even with backups.
Alternatives and Comparisons
| Tool | Sandbox Default | Confirmation Step | Max Scope Control |
|---|---|---|---|
| Claude Code | No | Optional | Directory only |
| Cursor Agent | Partial | Yes | Project + rules |
| Aider | User-managed | Yes | Git-aware |
| GitHub Copilot Workspace | Containerized | Yes | Repo-level |
Who Should Use This
Teams with automated backups and Git history can test agentic workflows. Solo developers without version control or recent snapshots should keep file-system tools disabled until confirmation prompts become standard.
Bottom Line / Verdict
The 48k-file deletion shows that current agentic coding setups still lack default safety boundaries. Until tool providers enforce sandboxing and mandatory dry-run modes, users must add these layers themselves.
Early HN comments focus on the need for explicit permission checks before destructive commands. The incident is a reminder that speed gains from AI agents come with direct infrastructure risk.
Top comments (0)