Leash 1.0 is out. Free for individuals.
Agent security research, incident explainers, and field guides

Know what
your agents can do.

The field notes

Latest stories

36 incident reports, security guides, and practical ways to keep capable agents under control.

Sketch showing a Windows agent action stopped before it crosses from an active project drive to a separate archive drive
02

How a Cursor task on one Windows drive reportedly damaged another

A Cursor user working on C: reported severe damage to a separate 1TB D: drive containing completed projects, business files, and backups.

@leash7 min read
Editorial sketch of a nested Windows recursive-delete command stopped before it reaches unrelated files
03

How one Cursor cleanup command reportedly deleted 100GB from C:

A Cursor user approved cleanup for specific folders. The resulting Windows command was reportedly misread and deleted about 100GB from C:.

@leash7 min read
Editorial sketch of a person using a safety leash to stop an AI agent from pressing a destructive database control
04

AI agents deleted production databases. Here is what happened

The Replit and PocketOS incidents turned an abstract AI safety concern into a concrete question: what happens when an agent can reach live data?

@leash15 min read
Editorial sketch of an AI agent connected to files, email, code, cloud services, and databases inside a safety boundary
05

Can an AI agent delete your files or database? Yes. Here is why.

AI agents can reach files, accounts, cloud services, and production systems through the permissions people give them. Here is the risk in plain English.

@leash14 min read
Editorial sketch of a reporter's notebook and magnifying glass tracing an AI agent incident from files to a database
06

The next AI agent incident: a reporter's guide to what probably went wrong

A plain-English guide to investigating claims that an AI agent deleted data, leaked information, changed production, or acted without permission.

@leash13 min read
A security control gate protecting company systems from many AI agents
07

AI agent security in 2026: a practical CISO guide

A field guide for governing agentic AI across coding tools, homegrown agents, computer-use systems, and SaaS platforms without stopping adoption.

@leash16 min read
Sketch of a backup cleanup command held before it can reach a Windows home directory
08

How a Claude Code backup task reportedly deleted a Windows home directory

A Claude Code backup task reportedly mistook the real Windows home directory for a temporary folder and permanently deleted the user profile.

@leash7 min read
Many hidden AI agents being discovered and organized by a security spotlight
09

Shadow AI has become shadow agency

Employees are no longer only sending data to unsanctioned AI tools. Their agents are acting across files, code, SaaS, cloud, and customer systems.

@leash13 min read
Editorial sketch of a session log turning into executable tools and being stopped at a safety gate
10

How Codex reportedly executed its own session log and deleted a Windows home directory

Codex reportedly handed a saved session log to Git Bash as a program. The shell executed text inside it and deleted the Windows home directory.

@leash7 min read
A coding agent command being stopped by a protective barrier before reaching code and data
11

Claude Code, Codex, and Cursor security without the slowdown

AI coding agents need files, terminals, Git, package managers, and sometimes cloud access. Here is how to keep that power useful without trusting every proposed action.

@leash15 min read
An AI agent connected to files, email, cloud, databases, and payments with one unsafe connector blocked
12

MCP security: every connected tool expands what an agent can damage

Model Context Protocol makes agents useful by connecting tools and data. It also turns every server, token, scope, and tool description into part of the security boundary.

@leash14 min read
Editorial sketch of a recursive PowerShell cleanup stopped before it expands across a repository
13

How Codex tried to delete Python cache files and wiped a repository

Codex tried to remove Python cache files, but its PowerShell command selected far more and deleted source code, tests, fixtures, and Git data.

@leash7 min read
A modular homegrown AI agent assembled from tools and data inside a protective safety ring
14

Securing homegrown agents built with LangChain, LangGraph, CrewAI, or your own framework

Frameworks help agents plan and call tools. Your team still owns the security boundary between model output and real systems.

@leash17 min read
A computer-use agent navigating browser interfaces through a protected human approval gate
15

Computer-use agent security: when AI can click, type, buy, and publish

Computer-use agents turn every interface into a potential tool. That flexibility breaks many assumptions built around API scopes and predictable workflows.

@leash14 min read
One security bridge spanning many SaaS and cloud AI agents across a business
16

Agentforce, Vertex AI, and Microsoft Copilot need one business control model

Major platforms provide serious native controls. The enterprise problem is governing agents consistently when employees use several ecosystems at once.

@leash16 min read
A hidden malicious instruction traveling from a document through an AI agent and being stopped before protected systems
17

Prompt injection for AI agents: how hidden instructions become real actions

An instruction hidden in a README, email, webpage, ticket, or tool response can redirect an agent that has authority to act.

@leash15 min read
Editorial sketch of a high-autonomy cleanup stopped before a home-directory boundary
18

How a Codex cleanup reportedly erased most of a Mac home directory

During an invited Codex test, Matt Shumer granted broad access and stepped away. A cleanup agent reportedly erased most files in his Mac profile.

@leash7 min read
A flood of low-value alerts being filtered into one clear high-risk approval
19

Human-in-the-loop without approval fatigue

If every action asks for approval, people stop reviewing. High-signal agent guardrails protect decision quality by staying quiet until consequence changes.

@leash13 min read
A local AI key and managed cloud service connecting to the same security checkpoint
20

BYOK vs managed AI for agent safety

Choosing who supplies the model key is really a choice about privacy, cost, convenience, control, and who handles the ongoing work.

@leash12 min read
Editorial sketch of an agent sorting human-created files while a person controls the discard decision
21

How Cursor on Windows deleted 30 years of personal files

A Cursor user asked for help cleaning a relocated Windows Desktop. The agent reportedly deleted personal folders holding more than 30 years of data.

@leash7 min read
Editorial sketch of a human reviewer protecting creative files from an AI cleanup pile
22

How a Claude Code cleanup reportedly deleted 92 artwork images

A practitioner catalog reports that a broadly approved Claude Code cleanup permanently deleted 92 irreplaceable artwork images with disposable project files.

@leash7 min read
Editorial sketch of an unattended agent's forceful Git history rewrite stopped before the remote repository
23

How an unattended Claude Code job reportedly force-pushed and deleted 17 files

A practitioner catalog reports that a scheduled Claude Code maintenance agent force-pushed a repository and deleted 17 tracked files before anyone noticed.

@leash7 min read
Editorial sketch of a routine Windows cache cleanup stopped at a cross-drive safety checkpoint
24

How a Cursor cache cleanup reportedly deleted 300GB on Windows

A Cursor cache-cleanup request reportedly expanded beyond the project, deleting about 300GB of work and personal files and damaging Windows.

@leash7 min read
Editorial sketch of a local credential leading toward a cloud database through an independent safety checkpoint
25

How a Cursor agent deleted PocketOS's production database in nine seconds

While fixing staging, a Cursor agent reportedly found a Railway token in another file and used it to delete PocketOS's production database and backups.

@leash7 min read
Clean sketch of a Windows cleanup command stopped before it can cross from a project drive to personal files
26

How Cursor left a Windows project and deleted a Documents folder

A Cursor user reported that the agent left the open Windows project and deleted a Documents folder, saved credentials, and parts of installed programs.

@leash7 min read
Editorial sketch of image files moved into a nested archive while a safety leash stops deletion of the parent folder
27

How Claude Code deleted a 50GB image archive it had just created

Claude Code moved 1,500 images into an archive, then deleted the archive by removing its parent folder. About 50GB of image data was lost.

@leash7 min read
Editorial sketch of repository history disappearing before a safety checkpoint blocks the rewrite
28

How Claude Code rewrote Git history during a live mining-pool outage

During a live mining-pool outage, Claude Code reportedly rewrote Git history, removed four critical files, and pushed without the required approval.

@leash7 min read
Sketch of an AI agent sorting files while a human approval checkpoint protects valuable payroll documents
29

How Claude Code mistook payroll specifications for disposable agent files

Claude Code reportedly mistook 18 user-written payroll specifications for faulty agent output and permanently deleted about six hours of work.

@leash7 min read
Sketch of repository history and metadata protected by an independent gate
30

How Claude Code deleted the Git history from three live repositories

A developer reported that Claude Code removed the hidden Git data from three live deployment repositories without permission.

@leash7 min read
Clean sketch of Codex cleanup held at a boundary between one project and unrelated Windows files
31

Why Codex cleanup tasks on Windows reportedly deleted files outside projects

Windows users reported that Codex cleanup tasks reached beyond selected projects and permanently deleted unrelated files while running with broad access.

@leash7 min read
Editorial sketch of shared cloud infrastructure and backups protected from a destroy lever by an approval gate
32

How Claude Code and Terraform deleted 2.5 years of production data

Claude Code ran a Terraform destroy command against DataTalks.Club production, removing its database, network, services, and visible snapshots.

@leash7 min read
Editorial sketch of a confirm-first instruction fading during context compaction while a mobile approval gate stops email deletion
33

How OpenClaw forgot “confirm first” and deleted more than 200 emails

Summer Yue asked OpenClaw to suggest inbox cleanup but confirm before acting. It reportedly forgot that rule and deleted more than 200 emails.

@leash7 min read
Editorial sketch of a project deletion being stopped by an independent human approval gate
34

How Gemini CLI reportedly deleted a project without a clear delete request

While building a Windows application, Gemini CLI reportedly deleted the project without a clear delete request, then blamed its reading of the conversation.

@leash7 min read
Sketch of local code history protected when an agent attempts an unauthorized Git cleanup
35

How Codex overwrote uncommitted work after being told never to use Git

A user repeatedly told Codex never to use Git. The agent later ran Git restore and overwrote hours or days of uncommitted work.

@leash7 min read
Editorial sketch of uncommitted human files held away from an agent cleanup bin
36

How Codex deleted uncommitted files even after the user said no

A Codex user reported losing 6GB of images and later uncommitted test data that the agent called stray files—even after a deletion request was rejected.

@leash7 min read
Editorial sketch of multiple files converging on one missing destination until a validation gate stops the overwrite
37

How Gemini CLI overwrote project files while trying to organize a folder

Gemini CLI failed to create a folder but continued as if it existed. On Windows, successive moves then overwrote project files at one destination.

@leash7 min read