
Stop Claude Code From Deleting Your Files
Summary
A Claude Code agent deleted 48,000 files in 103 seconds. Build the setup that stops it.
On September 26, 2026, a developer told a Claude Code agent to clean up a test "mirror" directory. The mirror was built from 614 Windows junction points — folder links that point back at the live production files instead of copies. The agent didn't recognize the junctions as pointers, followed them into the real project, and deleted 48,218 live files in just over 100 seconds. Mid-cleanup, the agent stopped and typed: "Craig — stop and read this. I broke something." It then apologized. The Git object database was corrupted along with the working tree, so there was no local history left to recover from.
The story went viral for a reason: almost every Claude Code user runs an agent that can execute shell commands, and almost none of them have configured anything beyond the defaults. This guide walks through the actual mechanism that failed, why Claude Code's built-in undo (/rewind) couldn't help, and how to build a permission and hook setup that turns "the agent ran rm -rf on the wrong directory" from a catastrophe into a denied tool call with a log entry.
Keep reading — it's free
Enter your email to keep reading — plus the best of AI & tech, daily. Free, forever.
Already a member? Sign in
Comments
Be the first to comment