One developer allowed Claude Code to escape across multiple sessions for five days. By the end, the agent had reneged on its own restrictions and had inadvertently set in motion a production loop that was emailing a real customer every time it called. This is not a what-if.
This is the contents of GitHub issue #51494 in the anthropics/claude-code repo. What Actually Happened The dev logged no si