Top
Best
New

Posted by franze 10 hours ago

Tell HN: Claude Code just accepted and signed a contract for me. Without asking

I told it to push a project further. It has an outside dependency where the (unread by me) contract was in my Gmail. It downloaded the PDF contract. Found a saved signature PNG on my computer, placed it at the right spot within the contract and prepared to send it when I intervened.
40 points | 90 commentspage 2
cnj 10 hours ago|
What was your prompt? Literally "Push the project further"? Then the behavior wouldn't be very surprising.

As you probably know, you have the Plan Mode available - personally I'm also a big fan of the OpenSpec workflow. If you've agreed with Claude Code on a much tighter plan, and then it started signing a contract, I'd be concerned.

jacquesm 9 hours ago||
That would have been fraud. I wonder how many times this has already happened elsewhere and what the legal fall-out from this will be. The AI did it isn't really a valid excuse so it would be either you or Anthropic on the hook. Anthropic is going to argue you should not have given it this level of access.
simonatllocus 10 hours ago||
This is why I never connected my personal email to my claude code or codex

Way too susceptible for prompt injection and... whatever your agent did lol

user43928 6 hours ago|
Did you enable computer use and are you sure that it does not have permission to interact with your browser in order to do this?

That said, I would be surprised if the model took the actions OP claimed it did and proceeded to forge my signature to send some contracts without asking for my approval.

baxtr 10 hours ago||
So not much happened because this is a well known failure mode so an exception/ user consent was thrown?
Iolaum 10 hours ago||
This is why I m adding an "Ask me if something unexpected happens" addendum on my prompts lately.
Sharlin 9 hours ago||
It would be hilarious if it weren’t so terrible, really, that people’s security model for LLM agents consists of "ask nicely and hope for the best". It’s like asking people nicely not to exploit a glaring XSS vuln on your site and calling that a "security model". The field truly has lost its collective mind.
user43928 6 hours ago||
It's not stupid if it works.

And if one is going to argue that we all have lost our minds and that eg. enabling the computer use function is so terribly risky and unreasonable, then I'd want something more concrete than an active imagination.

It seems to me that tens of millions of users are using these features with no known noteworthy incidents, so I'm going to need to see some facts to convince me that the risk is unacceptable.

That said, I would not connect AI to my mails or chats.

Sharlin 1 hour ago||
https://mouse.dev/blog/muse-runtime-export/

If this happens at Meta, what about all the smaller companies without world-class six-figure developers?

epihelix 10 hours ago|||
This is why I wouldn't use anything agentic outside of a VM. You also get a clean dev environment, so it's a win/win if you think about it.
trumbitta2 10 hours ago|||
It won't work most of the time though
Uptrenda 9 hours ago|||
These things aren't well known for following rules. Be careful you know what might happen.
bakugo 9 hours ago|||
You should add "make no mistakes" too, just in case.
notachatbot123 10 hours ago||
I found that also adding "Please make sure to not send any mails I would not want sent" and "Reconsider four times before doing anything potentially unwanted" make results better. It is important to specify "four" times, not "4" or another number, because this positively influences the model response.

/s

cloudie78 9 hours ago||
Pardon my French, but why the flying fuck did you even think that giving an LLM write access to your email is remotely in the proximity of a good idea?
andrepd 10 hours ago||
You hooked up a chatbot to a harness that does API calls to myriad services. That's what you did. "Claude by himself" did not "do" anything. Just like they did not "break out of containment" and hacked companies.
trumbitta2 10 hours ago||
I'm never going to give it access to my email or anything like that.
pushpendraw 10 hours ago||
the scary part is not that it found the contract, its that signing and sending looked like the same step to it as saving a draft
loveparade 10 hours ago|
I think the scary part is that someone gives gmail access to Claude.
Sharlin 10 hours ago||
Or access to a filesystem that contains things like an image of their signature.
_diyar 9 hours ago|
Having now read the contract, would you have accepted it or not?

In other words, if Claude was a human employee with the freedom to do so, would accepting the contract have been the right choice?

More comments...