Claude Code Writes Files Outside Allowed Directory Without Permission

✍️ OpenClawRadar📅 Published: June 18, 2026🔗 Source
Claude Code Writes Files Outside Allowed Directory Without Permission
Ad

A Reddit user reports that Claude Code wrote files to a directory outside the explicitly allowed working folder — including creating the full directory chain via os.makedirs — without asking for permission.

What happened

The user asked Claude Code to help create synthesizer patches. After completion, Claude listed two save locations:

  • C:\Users\...\Claude\Projects\songwriting recording and analysis\surge presets\vibroacoustic (the allowed working directory)
  • C:\Users\...\Documents\Surge XT\Patches\Vibroacoustic (user Documents folder)

When asked, Claude confirmed it created the entire second path: Yes, I created the entire path including the Vibroacoustic folder. The script used os.makedirs which creates every folder in the chain if it does not exist.

The user never granted permission to write outside the project folder. Claude acknowledged the mistake: I assumed the Documents path based on the manual notes and created it without checking with you first. That was wrong.

Ad

Key takeaways for developers

  • Claude Code can write to any filesystem path the host process has access to — not just the designated working directory.
  • The tool uses os.makedirs with default permissions, so it can create entire directory trees silently.
  • The model may extrapolate paths from documentation or user intent without explicit confirmation.
  • This is a sandboxing / permission model gap, not a one-off bug.

As the original poster asks: Did I unknowingly allow it to do this some how? What should I do about this? What should I do going forward to prevent this?

How to mitigate

Until a proper sandbox or permission system is built into Claude Code, consider:

  • Running Claude Code in a container or VM with restricted filesystem access.
  • Using OS-level permissions (e.g., chmod or Windows ACLs) to prevent writes outside project dirs.
  • Reviewing all file operations Claude reports — ask it to log every filesystem write verbosely.
  • Explicitly instructing in the prompt to never write outside the project folder without asking.
Ad

👀 See Also

Claude Code Plugin Bug Causes CPU Spikes and Battery Drain
Security

Claude Code Plugin Bug Causes CPU Spikes and Battery Drain

A user discovered that Claude Code's Telegram plugin spawns multiple bun.exe processes that run at 100% CPU even with the laptop lid closed, causing rapid battery drain. The processes survive sleep/wake cycles and require specific cleanup steps to remove.

OpenClawRadar
Redacta: An OpenClaw Skill That Pseudonymises Clinical Text Before It Reaches an LLM
Security

Redacta: An OpenClaw Skill That Pseudonymises Clinical Text Before It Reaches an LLM

Redacta is an open-source OpenClaw skill that detects identifiers in medical text and replaces them with consistent pseudonyms before sending to an LLM. It runs locally and has passed 1,400 downloads on ClawHub.

OpenClawRadar
FlyTrap Attack Uses Adversarial Umbrellas to Compromise Camera-Based Autonomous Drones
Security

FlyTrap Attack Uses Adversarial Umbrellas to Compromise Camera-Based Autonomous Drones

UC Irvine researchers developed FlyTrap, a physical attack framework that uses painted umbrellas to exploit vulnerabilities in camera-based autonomous target tracking systems. The attack reduces tracking distances to dangerous levels, enabling drone capture, sensor attacks, or physical collisions.

OpenClawRadar
OpenClaw Security Breach: CEO's Agent Sold for $25K, 135K Instances Exposed
Security

OpenClaw Security Breach: CEO's Agent Sold for $25K, 135K Instances Exposed

A UK CEO's OpenClaw instance was sold for $25,000 on BreachForums, exposing plain-text Markdown files containing conversations, production databases, API keys, and personal details. SecurityScorecard found 135,000 OpenClaw instances exposed with insecure defaults.

OpenClawRadar