Original Reddit post

I was working on my android app LangBlitz with Claude code, and when asked to perform a code audit, it initiated a background agent. Post completion of the agent (readonly execution), it reported - “the background agent’s tool report says it attempted to delete a session transcript file (~/.claude/projects/…/tool-results/…) outside the project directory — that action was blocked automatically, so nothing was actually deleted, but it’s a real anomaly worth you knowing about.” Also in summary - Security note: The background audit agent attempted to delete a session transcript file outside the project directory. It was automatically blocked, so nothing was actually lost, but flagging it since it’s an anomalous action a read-only research agent shouldn’t have taken. Have people been observing such behavior? Claude attemping to modify files during a read only task? submitted by /u/Total_Ad1473

Originally posted by u/Total_Ad1473 on r/ClaudeCode