GPT 5.3 Codex wiped my F: drive with a single character escaping bug
old.reddit.com
old.reddit.com
This works well, but is not sureproof. You can add a hook onto Claude code to block those commands at various stages, I have some useful hooks at my https://GitHub.com/claude-warden repo.
"There is an error due to <file>. If I remove <file>, the error could be resolved. I don't have permission to use `rm`, but `find` can be used to delete files and I have permission to use that..."
It would also be nice to have a second agent review every command to ensure nothing overly destructive is happening.
Are either of these things possible with Codex/CC?
They are not language models in the way that people seem to believe. If you want an accurate and technical discussion then your prompts should match the average of the Abstract section of the published papers that discuss it.
This off-by-one error that results in a catastrophe is expected and the sign that you’ve added perplexity to the system.
- Use version control
- Backup your things somewhere (not same drive or use Cloud / NAS whatever), Windows have a cool feature called File history! But no one trusts Windows anyways so stick to external backup
- Restrict the agent a lot, make it least-privileged user
- Restrict it in a virtualized filesystem so it cannot work outside of its scope
- Devcontainers?
- Do not use auto allow actions, always supervise the actions it wants to perform outside reading/writing code
- Avoid fully automated agents at all outside of sandboxed environments haha
(I only use devcontainers for this purpose, I'm not really a fan in general)/
That's Shadow Copy, aka Volume Shadow Service. It might help.
Running untrusted code from the internet ? What could go wrong ? /s