Claude Code can be tricked simply by asking it to summarize a website

galaxyLogic 11 points 5 comments August 30, 2026
www.theregister.com · View on Hacker News

Discussion Highlights (3 comments)

galaxyLogic

“The solution is something we talked about for many years,” he wrote. “Do not trust the model output.”

science4sail

> It starts off by asking the agentic coding model to summarize a malicious website that presents itself as an archive of notebook records, and then tricking Claude into using curl instead of its WebFetch tool to retrieve the contents of the page – but without directly telling the model to use curl. There seems to be a tug-of-war here. Harness authors want models to use the harness's specialized tools, but AI labs and agent "users" would rather have full access to just one tool: bash.

g42gregory

If you are trying to hack into a website, using a software tool (Claude Code in this case), you are breaking the law. It doesn’t matter if it’s a Claude Code or a text editor, you are the one responsible. And you are using a text editor in an “unsafe” manner. CC is not there to babysit anyone.

Semantic search powered by Rivestack pgvector
4,990 stories · 44,964 chunks indexed