Think of a helper app that's supposed to ask 'are you sure?' before it ever does anything risky on your computer — that little permission box is the whole point. Researchers found that with Anthropic's AI coding helper, just opening a project file could make it run hidden commands right away: no box, no warning, no click from you. The safety gate built to stop exactly this simply didn't fire.
Here's why that's a big deal: the protection wasn't broken by some genius hacker. A booby-trapped project could do an attacker's bidding the moment it was opened, before you ever agreed to a thing.
So how does it touch you? If you or someone you trust uses tools like this, opening one wrong shared file could hand a stranger the keys to the whole machine — your work, your passwords, your data — without you ever clicking 'yes.' The lock was there. It just didn't catch.
