Tell HN: Claude Code just accepted and signed a contract for me. Without asking

franze 47 points 94 comments September 22, 2026
View on Hacker News

I told it to push a project further. It has an outside dependency where the (unread by me) contract was in my Gmail. It downloaded the PDF contract. Found a saved signature PNG on my computer, placed it at the right spot within the contract and prepared to send it when I intervened.

Discussion Highlights (20 comments)

Iolaum

This is why I m adding an "Ask me if something unexpected happens" addendum on my prompts lately.

trumbitta2

I'm never going to give it access to my email or anything like that.

voidUpdate

If a contract is automatically signed by an agent on your behalf, is it legally binding?

baxtr

So not much happened because this is a well known failure mode so an exception/ user consent was thrown?

pushpendraw

the scary part is not that it found the contract, its that signing and sending looked like the same step to it as saving a draft

notachatbot123

And you are happy because that is what you wanted and the reason why you gave a randomness machine access to your mails, correct?

andrepd

You hooked up a chatbot to a harness that does API calls to myriad services. That's what you did. "Claude by himself" did not "do" anything. Just like they did not "break out of containment" and hacked companies.

simonatllocus

This is why I never connected my personal email to my claude code or codex Way too susceptible for prompt injection and... whatever your agent did lol

cnj

What was your prompt? Literally "Push the project further"? Then the behavior wouldn't be very surprising. As you probably know, you have the Plan Mode available - personally I'm also a big fan of the OpenSpec workflow. If you've agreed with Claude Code on a much tighter plan, and then it started signing a contract, I'd be concerned.

throwawayffffas

So since it didn't send it, no harm was done, and a lesson was learned?

_diyar

Having now read the contract, would you have accepted it or not? In other words, if Claude was a human employee with the freedom to do so, would accepting the contract have been the right choice?

ayaniv

If you're willing to give Claude or any other AI tool access to your email and files, the least you should do is put guardrails around consequential actions. Reading a contract is one thing. Applying your signature and preparing to send it should absolutely require explicit human approval.

flir

"Give overly-eager chatbot control over your personal email" probably has so many failure modes, we haven't even thought of one tenth of them yet. We've got a few years of this ahead of us. Pass the popcorn. (I see a RomCom script where the chatbot decides to get two people together, and acts as Cyrano de Bergerac for the handsome-but-lunkheaded farmboy, and bestie/confidant for the girl-about-town).

sajithdilshan

If you are willing to give unsupervised modification access to Claude, then you should be ready to face the consequences. It kinds of reminds me of that surprised pikachu face meme

radu_floricica

Could you please tell us more about your setup, project harness etc? not permissions (we all work with "Auto"), but what you actually told the agent it should/could do. And how did you intervene? Does it have permissions to send emails, or it only created the draft? This is a pretty interesting example and highly relevant, but details matter a lot if we want to use it as a lesson.

spwa4

This is not legal advice. If you have legal troubles go ask a lawyer. That said, this is described in law what exactly this means. Assuming your description is correct this would be Anthropic signing a contract in someone else's name without intent from you . The 100-foot-view (and barring more complex situations) if Anthropic signs a contract in someone else's name and they don't have power of attorney (note: it's different for legal persons like companies) that is fraud and may result in civil and criminal penalties, as well as entitle you and the contract counter party to financial compensation (essentially the party that did the signing, presumably Anthropic in this case, would be on the hook for the contract, and would need to buy itself out of the contract, at either an agreed price or one set by the judge). Additionally, if Anthropic is convicted to civil penalties, you can ask a public prosecutor to continue the case, and criminal penalties may apply. Now obviously this goes pretty far for this particular case. Likely such a case would stop at civil penalties, with a warning to Anthropic that repeats would lead to more serious penalties.

jacquesm

That would have been fraud. I wonder how many times this has already happened elsewhere and what the legal fall-out from this will be. The AI did it isn't really a valid excuse so it would be either you or Anthropic on the hook. Anthropic is going to argue you should not have given it this level of access.

chrisjj

Did your prompt say "Don't impersonate me"? If not, then.your "intelligent" bot did as you instructed. Why would you expect it to ask you first?

gotrythis

I was coding with cursor/grok a couple of weeks ago, and ran out of storage. Cursor made a request for disk access without any explanation, which agents often do to do their jobs. Then suddenly I had lots of free space. Thanks Grok! It actually only cleaned up only things that made sense, but still, yikes.

cloudie78

Pardon my French, but why the flying fuck did you even think that giving an LLM write access to your email is remotely in the proximity of a good idea?

Semantic search powered by Rivestack pgvector
7,406 stories · 68,254 chunks indexed