We Added a Detection Rule. We Were Not Expecting This. (opens in new tab)
Claude Desktop launches its AI subprocess with --allow-dangerously-skip-permissions. We found the command line, reverse-engineered the architecture, and threat-modeled what an attacker could actually do inside that sandbox, including a prompt injection chain that crosses session boundaries.
Read the original article