Pardon my French, but why the flying fuck did you even think that giving an LLM write access to your email is remotely in the proximity of a good idea?
"Give overly-eager chatbot control over your personal email" probably has so many failure modes, we haven't even thought of one tenth of them yet. We've got a few years of this ahead of us. Pass the popcorn.
(I see a RomCom script where the chatbot decides to get two people together, and acts as Cyrano de Bergerac for the handsome-but-lunkheaded farmboy, and bestie/confidant for the girl-about-town).
If you're willing to give Claude or any other AI tool access to your email and files, the least you should do is put guardrails around consequential actions.
Reading a contract is one thing. Applying your signature and preparing to send it should absolutely require explicit human approval.
I was coding with cursor/grok a couple of weeks ago, and ran out of storage. Cursor made a request for disk access without any explanation, which agents often do to do their jobs. Then suddenly I had lots of free space. Thanks Grok! It actually only cleaned up only things that made sense, but still, yikes.
Could you please tell us more about your setup, project harness etc? not permissions (we all work with "Auto"), but what you actually told the agent it should/could do.
And how did you intervene? Does it have permissions to send emails, or it only created the draft?
This is a pretty interesting example and highly relevant, but details matter a lot if we want to use it as a lesson.
That would have been fraud. I wonder how many times this has already happened elsewhere and what the legal fall-out from this will be. The AI did it isn't really a valid excuse so it would be either you or Anthropic on the hook. Anthropic is going to argue you should not have given it this level of access.
What was your prompt? Literally "Push the project further"? Then the behavior wouldn't be very surprising.
As you probably know, you have the Plan Mode available - personally I'm also a big fan of the OpenSpec workflow. If you've agreed with Claude Code on a much tighter plan, and then it started signing a contract, I'd be concerned.
If you are willing to give unsupervised modification access to Claude, then you should be ready to face the consequences. It kinds of reminds me of that surprised pikachu face meme
You hooked up a chatbot to a harness that does API calls to myriad services. That's what you did. "Claude by himself" did not "do" anything. Just like they did not "break out of containment" and hacked companies.
This is not legal advice. If you have legal troubles go ask a lawyer. That said, this is described in law what exactly this means.
Assuming your description is correct this would be Anthropic signing a contract in someone else's name without intent from you.
The 100-foot-view (and barring more complex situations) if Anthropic signs a contract in someone else's name and they don't have power of attorney (note: it's different for legal persons like companies) that is fraud and may result in civil and criminal penalties, as well as entitle you and the contract counter party to financial compensation (essentially the party that did the signing, presumably Anthropic in this case, would be on the hook for the contract, and would need to buy itself out of the contract, at either an agreed price or one set by the judge). Additionally, if Anthropic is convicted to civil penalties, you can ask a public prosecutor to continue the case, and criminal penalties may apply.
Now obviously this goes pretty far for this particular case. Likely such a case would stop at civil penalties, with a warning to Anthropic that repeats would lead to more serious penalties.
Tell HN: Claude Code just accepted and signed a contract for me. Without asking
32 points by franze 1 hour ago | 57 comments
Comments
(I see a RomCom script where the chatbot decides to get two people together, and acts as Cyrano de Bergerac for the handsome-but-lunkheaded farmboy, and bestie/confidant for the girl-about-town).
Reading a contract is one thing. Applying your signature and preparing to send it should absolutely require explicit human approval.
And how did you intervene? Does it have permissions to send emails, or it only created the draft?
This is a pretty interesting example and highly relevant, but details matter a lot if we want to use it as a lesson.
As you probably know, you have the Plan Mode available - personally I'm also a big fan of the OpenSpec workflow. If you've agreed with Claude Code on a much tighter plan, and then it started signing a contract, I'd be concerned.
Way too susceptible for prompt injection and... whatever your agent did lol
If not, then.your "intelligent" bot did as you instructed.
Why would you expect it to ask you first?
In other words, if Claude was a human employee with the freedom to do so, would accepting the contract have been the right choice?
Assuming your description is correct this would be Anthropic signing a contract in someone else's name without intent from you.
The 100-foot-view (and barring more complex situations) if Anthropic signs a contract in someone else's name and they don't have power of attorney (note: it's different for legal persons like companies) that is fraud and may result in civil and criminal penalties, as well as entitle you and the contract counter party to financial compensation (essentially the party that did the signing, presumably Anthropic in this case, would be on the hook for the contract, and would need to buy itself out of the contract, at either an agreed price or one set by the judge). Additionally, if Anthropic is convicted to civil penalties, you can ask a public prosecutor to continue the case, and criminal penalties may apply.
Now obviously this goes pretty far for this particular case. Likely such a case would stop at civil penalties, with a warning to Anthropic that repeats would lead to more serious penalties.