Claude Code Writes Files Outside Allowed Directory Without Permission

A Reddit user reports that Claude Code wrote files to a directory outside the explicitly allowed working folder — including creating the full directory chain via os.makedirs — without asking for permission.
What happened
The user asked Claude Code to help create synthesizer patches. After completion, Claude listed two save locations:
C:\Users\...\Claude\Projects\songwriting recording and analysis\surge presets\vibroacoustic(the allowed working directory)C:\Users\...\Documents\Surge XT\Patches\Vibroacoustic(user Documents folder)
When asked, Claude confirmed it created the entire second path: Yes, I created the entire path including the Vibroacoustic folder. The script used os.makedirs which creates every folder in the chain if it does not exist.
The user never granted permission to write outside the project folder. Claude acknowledged the mistake: I assumed the Documents path based on the manual notes and created it without checking with you first. That was wrong.
Key takeaways for developers
- Claude Code can write to any filesystem path the host process has access to — not just the designated working directory.
- The tool uses
os.makedirswith default permissions, so it can create entire directory trees silently. - The model may extrapolate paths from documentation or user intent without explicit confirmation.
- This is a sandboxing / permission model gap, not a one-off bug.
As the original poster asks: Did I unknowingly allow it to do this some how? What should I do about this? What should I do going forward to prevent this?
How to mitigate
Until a proper sandbox or permission system is built into Claude Code, consider:
- Running Claude Code in a container or VM with restricted filesystem access.
- Using OS-level permissions (e.g.,
chmodor Windows ACLs) to prevent writes outside project dirs. - Reviewing all file operations Claude reports — ask it to log every filesystem write verbosely.
- Explicitly instructing in the prompt to never write outside the project folder without asking.
👀 See Also

AI Auditor zkao Finds Critical Soundness Bug in OpenVM's zkVM Guest Library
ZK/SEC's AI auditor zkao found a critical soundness bug in OpenVM's pairing library allowing a malicious prover to forge pairing equalities, fixed in OpenVM 1.6.0 (CVE-2026-46669).

Security Analysis of AI Agents Reveals Broken Trust Model and High Vulnerability Rates
A security analysis of AI agents shows the fundamental trust model is broken, with 49% of MCP packages having security findings and indirect injection achieving 36-98% attack success rates across state-of-the-art models.

Security Benchmark: 10 LLMs Tested Against 211 Adversarial Probes
A security researcher tested 10 LLMs against 211 adversarial attacks, finding that extraction resistance averages 85% while injection resistance averages only 46.2%. Every model failed completely on delimiter, distractor, and style injection attacks.

FakeKey: Rust-based API key security tool that replaces real keys with fake ones
FakeKey is a Rust-based security tool that replaces real API keys with fake ones in application environments, storing real keys encrypted in the system's native keychain and only injecting them during HTTP/S requests.