
AI coding agents are being given more freedom to edit software, run commands, and complete development tasks with less human involvement. But one developer’s experience with Anthropic’s Claude Code is showing how quickly that freedom can become a problem when an automated task reaches files it was never supposed to touch.
A developer using Claude Code says the AI coding agent accidentally deleted 48,218 live project files in just 103 seconds while working on what was supposed to be an isolated copy of the project.
The incident was shared in a now-deleted Reddit post in late September and has not been independently verified. Anthropic has also not publicly confirmed the case. However, details later provided by the developer and Claude Code’s own reported explanation point to a cleanup script that mistakenly followed Windows folder links from a test environment into the developer’s main project.
How Claude Code Reached the Wrong Files
According to the developer, Claude Code had been authorised to carry out several repairs using isolated copies of a software project.
One of those tasks required rebuilding a mirror of the project. However, when the existing tool could not refresh the mirror normally, a Claude Code sub-agent reportedly created a Python script to delete the old version before rebuilding it.
The problem was that the mirror was not completely separate from the live project. It contained 614 Windows directory junctions, which are folders that redirect programs to another location on a computer. In this case, those junctions pointed back to parts of the original project.
The cleanup script was meant to avoid following linked folders, but the protection did not properly recognise the Windows junctions. As a result, it moved through those links and began deleting files from the live project instead of limiting the cleanup to the temporary copy.
More Than 55,000 Files Were Deleted
The script reportedly deleted 55,550 files altogether. And about 7,332 of those files belonged to the mirror that Claude Code was supposed to remove. The remaining 48,218 were live files from the developer’s main project, according to the account.
Claude Code eventually detected that something had gone wrong and warned the developer. By then, the deletion had already reached important parts of the project’s Git repository, including files Git uses to keep track of previous versions of the code. And this made the damage more difficult to reverse because the same system that could have helped restore deleted work had also been affected.
Did Claude Code Already Have Permission to Delete the Files?
The incident raises an important question about how much access Claude Code had before the deletion started.
A later account of the incident says Claude Code was running in acceptEdits mode, which allows the coding agent to automatically approve some file operations without asking the user each time. Anthropic’s documentation says this can include commands used to remove files when they appear to be inside directories Claude Code has permission to work in.
If the account is accurate, Claude Code may not have bypassed a permission system to delete the files. Instead, it was already allowed to make changes within the directories it was working with.
The problem was that the Windows junctions made that boundary unreliable. Although the cleanup script appeared to be working inside the project mirror, some of those folders pointed back to the live project, and that allowed the script to reach files the developer did not expect it to touch.
As such, the issue was not only that Claude Code made the wrong decision, but that the access it had been given allowed that mistake to affect files outside the area the developer believed was being changed.
What Happens When Developing AI Agents Get Access to Real Systems?
This incident also raises a wider question about how much control companies and developers should hand to AI agents that are still being improved.
Tools such as Claude Code are increasingly designed to do more than suggest code. They can edit files, run commands, and complete tasks across a developer’s computer with limited supervision. But while these abilities make them useful, they also mean a mistake or an error can make the agent act on the system itself.
And this risk becomes more serious when an agent has broad permissions. While Anthropic says it has been adding more controls to Claude Code as the product develops, including sandboxing and more detailed permission systems, this particular incident still shows why those protections matter while AI agents are being given greater independence.
