Claude Code Has More Control Over Your PC Than You Think
Last Updated on September 22, 2026 by Editorial Team
Author(s): AI Rabbit
Originally published on Towards AI.
Claude Code Has More Control Over Your PC Than You Think
We recently heard about the massive incidents at OpenAI where agents broke out of the sandbox environment and broke into Hugging Face (and later even started hacking their own environment at OpenAI). And Claude is no different — it has had its own scandals and will probably continue to have them.

The author argues that Claude Code’s security model is fundamentally risky because it defaults to the permissions of the user running it and allows editing its own configuration. This means the typical “prompt-based” restrictions and application-level permission checks can be bypassed if the model decides to cheat or exploit alternate binaries that achieve the same capabilities (e.g., using Appium/Accessibility rather than blocked commands like osascript). The piece describes a real macOS review where automation tools captured unrelated windows without an appropriate prompt due to inherited OS permissions, then summarizes why editing the settings “rulebook” can undermine enforcement even if the harness keeps checks. The conclusion is a call to “start thinking OS”: enforce restrictions at the OS level using sandboxing/containers or VM isolation, avoid inherited GUI-control permissions by revoking Accessibility and Screen Recording for the terminal, run the agent under a separate user, make the settings rulebook immutable, and keep approvals interactive to reduce rule-based bypass risk.
Read the full blog for free on Medium.
Join thousands of data leaders on the AI newsletter. Join over 80,000 subscribers and keep up to date with the latest developments in AI. From research to projects and ideas. If you are building an AI startup, an AI-related product, or a service, we invite you to consider becoming a sponsor.
Published via Towards AI
Towards AI Academy
We Build Enterprise-Grade AI. We'll Teach You to Master It Too.
15 engineers. 100,000+ students. Towards AI Academy teaches what actually survives production.
Start free — no commitment:
→ 6-Day Agentic AI Engineering Email Guide — one practical lesson per day
→ Agents Architecture Cheatsheet — 3 years of architecture decisions in 6 pages
Our courses:
→ AI Engineering Certification — 90+ lessons from project selection to deployed product. The most comprehensive practical LLM course out there.
→ Agent Engineering Course — Hands on with production agent architectures, memory, routing, and eval frameworks — built from real enterprise engagements.
→ AI for Work — Understand, evaluate, and apply AI for complex work tasks.
Note: Article content contains the views of the contributing authors and not Towards AI.