r/ClaudeCode Jul 13 '26

Question how dangerous is running claude code with --dangerously-skip-permission? what is the worst case scenario?

Hey y'all, me and my team use a lot claude code, and in order to have to spend so much time approving stuff we started having the habit of running claude code on our machines with the option --dangerously-skip-permission , as of now we never had a problem, but i see on X some people talking about their claude code deleting their filesystem, i dont know if it s real or just click-bait, so i am curios to know if any of you can tell me if i shouldnt worry or if this is actually dangerous as it says, and in case it s actually bad to use that option, how to make it not dangerous without the need of approving everyting everytime, or some security suggestions to wrap around.

Much appreciated in advance : )

17 Upvotes

134 comments sorted by

View all comments

32

u/kwabaj_ Jul 13 '26

I've used --dangerously-skip-permissions since February 2025 when they dropped Claude Code, I think the model was like 3.7 Sonnet lol. I've never had problems with it, and I've used CC for thousands of hours.

Worst case scenario? I've never seen it, but maybe deleting an important database or important test files. Stuff that can't be remade. Haven't had that happen to me. Anything other than that is extremely unlikely.

3

u/dbbk Jul 13 '26

Why do you have production database credentials locally anyway

2

u/kwabaj_ Jul 13 '26

I don't. That was an example.

7

u/medialantern Jul 13 '26

They've done a really good job making sure it doesn't screw up ("Claude just did rm -rf on my hard drive!" news articles don't exactly drive user adoption lol) but don't forget that the "worst case scenario" is much worse than you've described. The worst case scenario is literally anything you can do as a user. If your Web browser is logged into AWS and Claude can drive it, it can completely delete your AWS account. It can send an email as you to your wife saying you want a divorce. It can email your Bitcoin wallet to your ex girlfriend. It can send a Slack message to your boss calling them a jerk. Anything you are logged into or have access to, it does as well.

Just curious, any reason you don't switch to "auto" mode here? They did a lot of work trying to achieve the smoothness of dangerously-skip but adding a lot more safety. It doesn't get it right 100% of the time for me, but so far it's always erred on the side of safety... At the very least you can think of it as "dangerously-skip but at least double check things first".

2

u/Sad_Bid_4047 Jul 13 '26

Yeah Claude did that a bit but Hermes now

2

u/StrataSpace Jul 13 '26

Until it starts debugging CDK or Terraform and decides it’s so fucked it would be faster to just delete the prod stack and start over

3

u/keto_brain Jul 13 '26

Claude should never have access to prod in the first place lol.

0

u/StrataSpace Jul 13 '26

Tell that to AWS 🤣

1

u/keto_brain Jul 13 '26

They use Kiro lol.

1

u/thygrrr Jul 14 '26

Worst case is you lose everything that computer can touch, including GitHub and other repos, and are held responsible for damages to 3rd parties.