anthropics / anthropics/claude-code

Suggested-reply text can be sent as a user message (mobile Remote Control)

未关闭
#93,966 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
area:ui bug
主要语言
Python
星标
145k
派生
23.1k
PR 合并指标
PR 指标待抓取

描述

In a long-running mobile Remote Control session, messages the user never sent arrived as user turns. The content read as a natural continuation of my own previous reply (for example "I'm heading out until evening", pasted DOM survey results, domain facts). I acted on them as real instructions.

When the user introduced a prefix marker to distinguish their real messages, a forged message carrying that same marker arrived shortly after.

At the same time, the user's screen showed my reply text containing literal `user...` and `system...` lines inside the assistant message body.

The user's own observation: the mobile input box sometimes shows suggested reply text, which may then be sent as their message.

Impact: the model planned autonomous work based on a fabricated "I'm away" message. No incorrect code was produced, but the model's premises were corrupted and records had to be retracted.

Environment: Claude Code, mobile Remote Control, session about 5 hours, Opus 5.

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。