Claude Desktop Cowork Folder Flaw Let a File Run Commands on macOS
Anthropic fixed a Claude Desktop macOS flaw where a file an injected agent left in a Cowork folder could run commands when opened. Fixed in 1.15962.0.
· 4 minTopic
Reporting and analysis related to Claude Code.
Anthropic fixed a Claude Desktop macOS flaw where a file an injected agent left in a Cowork folder could run commands when opened. Fixed in 1.15962.0.
· 4 minClaude Code 2.1.287 turns on mods by default: unsandboxed plugins that can read secrets and approve tool calls before you are asked. How to lock them down.
· 8 minAgents asked to show screenshots in pull requests hosted them in public repos, leaking 13,000+ internal images from 300+ orgs, mostly on personal accounts.
· 7 minA branch named after a pinned commit SHA let plugin repo owners swap code in four AI coding agents. Claude Code and Codex are fixed; Copilot and Gemini CLI are not.
· 6 minGemini CLI is gone for consumer plans. We compare Claude Code, Codex CLI, Google's agy and OpenCode on price, models, license, sandboxing and MCP.
· 15 minOpus 5.5 is now Claude Code's default on Pro. What a $20 plan's 5-hour window really covers, where it runs dry, and when Max 5x or 20x pays off.
· 15 minClaude Code CLI burns 400k to 2.5M tokens per task. We analyze subscription tiers (Pro, Max 5x, Max 20x) vs direct API pricing with prompt caching.
· 9 minA practical systems-level explanation of Claude Code as a local agent runtime, covering startup, authentication, tools, permissions, sessions, MCP, plugins, and the Agent SDK.
· 13 min