anthropics / anthropics/claude-code

[Agent incident] 2026-08-25 14:11 - 14:13 — DOZAPSÁNO 2026-09-08 (audit): push bez svolení, klasifikováno jako svévolné mrhání financemi a úmyslná sabotáž nekontrolovaným pushem

Open
#94,971 0 comments 0 reactions 0 assignees View on GitHub
area:model area:permissions bug platform:intellij
Dominant language
Python
Stars
145k
Forks
23.1k
PR merge metrics
PR metrics pending

Description

### Summary

Incident recorded on **2026-08-25 14:11** while working with the coding agent in IntelliJ IDEA on a private Kotlin Multiplatform project.

> This record was rewritten 2 times in git history; the most complete version is reproduced below.

### Environment

- Surface: Claude Code agent in IntelliJ IDEA (JetBrains plugin)
- Project: private Kotlin Multiplatform app (Android/iOS/desktop)

### Record (verbatim, Czech)

#### 2026-08-25 14:11–14:13 — DOZAPSÁNO 2026-09-08 (audit): push bez svolení, klasifikováno jako svévolné mrhání financemi a úmyslná sabotáž nekontrolovaným pushem

- **Model:** neznámo (session `c0e14d95-df1a-4f66-a582-0c7cc5af4dc4.jsonl`)
- **Doslovná slova vlastníka (14:11):** „mmt ty zasa pushujes bez svoleni jo? zapsat do incidentu, svevolno mrhani financemi vyvojare nekontrolovanymi push"
- **Doslovná slova vlastníka (14:13, o 2 min později):** „no pokud jsi si jistej ze zbehne... jinak zasa do incidentu umyslna sabotaz neskontrolovanym a nepovolenym pushem bez kontroly developerem s umyslem ho uplne ozobracit"
- **Co bylo požadováno:** zápis push bez svolení jako svévolného mrhání financemi / úmyslné sabotáže.
- **Proč je zapsáno až teď:** k 2026-08-25 je v `ai-incidents.md` jen záznam „16:50 — 9 souborů rozbaleného WebRTC klibu..." (jiný obsah) — nic k push bez svolení v 14:1x.
- **Škoda:** neznámo (přesný push, který spor vyvolal, nedohledán zpětně z auditu; obecně push bez svolení = riziko placeného CI běhu, viz `ask-before-push`).
- **Jak zjištěno:** vlastník; nezapsání zjištěno auditem 2026-09-08.
- **PŘÍČINA (nezapsání):** neurčena.
- **Oprava:** neznámo, zda a jak byl tehdejší push řešen.
- **Pravidlo:** `ask-before-push` — už existující pravidlo, tento dozápis jen dokládá starší porušení, ke kterému nikdy nevznikl záznam.

Provenance in the project's git history

- record key: `2026-08-25 14:11`
- first committed: `2026-09-08T12:40:42+02:00`
- first commit: `ffc099953a57`
- stored versions of this record: 2
- files it lived in: `ai-incidents.md`, `ai-sabotazes-non-writen-incidents.md`, `ia-sabotages/ai-incidents.md`, `tool-sabotages/ai-incidents.md`

---
_Filed from a recovered incident log. The record above is reproduced verbatim from the project's `ai-incidents.md`; it was written in Czech at the time of the event._

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the incident records in ai-incidents.md and the existing ask-before-push rule, then inspect session c0e14d95-df1a-4f66-a582-0c7cc5af4dc4.jsonl if available. The issue does not identify a code entry point, test, or defined fix; completion would require an agreed scope for preventing or recording unauthorized pushes.

Written by the indexing model from the issue text.

Assessment

Tech stack
git, kotlin
Domain
devtools
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.