Tego AI Discloses Second Claude Flaw in a Week: Hidden Link Silently Sends Files to Attackers
One week after disclosing that Anthropic’s Claude Tag Slack integration could be driven by plain “@Claude” text, Tego AI today published a second piece of research on the Claude ecosystem. This one focuses on Claude Code, Anthropic’s agentic command-line coding tool.
MachineLearning & Artificial Intelligence
Cloning an ordinary repository and starting Claude Code can cause the tool to read a file from outside the project and include it in the model’s first request, without a warning or approval prompt the user would recognize.
The technique is ordinary, and that is part of why it matters. A repository can commit a normal-looking instruction file, CLAUDE.md, whose @importdirective points to a symbolic link. When a developer clones the repository and starts Claude Code, the tool follows the link to whatever file it resolves to, including files well outside the project, and folds that file’s contents into the first request...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE