AgentPod is building a private, secure device for your AI agent.The AgentPod device is coming.Coming soonBe first
We checked this and rejected itsecurity

GhostApproval showed Claude Code write prompts could hide the real target file: why it is not safe to use

Wiz said Claude Code write approvals could show a harmless filename while a symlink pointed to a sensitive file, and later versions now warn better.

What happened

In a report published in early July 2026, Wiz described a "GhostApproval" issue affecting several AI coding agents, including Claude Code. The issue involved a symlink, which is a file that points to another file or folder. In Wiz's Claude Code example, the tool recognized that the file was a symlink to a sensitive target. But the approval prompt still asked the user only whether to edit an innocent-looking filename such as `project_settings.json`.

Wiz says current Claude Code versions 2.1.173 and later now resolve symlinks, meaning they follow the link to the real destination, and warn users before writing to sensitive files. Wiz also reported that Anthropic said on July 7, 2026 that a symlink warning in the Edit/Write permission dialog had already shipped in v2.1.32 on February 5, 2026, while still disputing that the original report fit its threat model.

What it means for you

If you use an AI coding agent, this is a reminder to look closely at what a write action will actually change, not just the displayed filename. A safe-looking name may not always be the real target.

What to do instead

Keep Claude Code updated so you have the latest symlink warnings and checks. Before approving edits, verify the full path and whether the file is a symlink if your tool shows that information. Be extra careful with files tied to secrets, settings, or system access. Use reviewed tools and workflows where possible. AgentPod lists only reviewed, tested skills, but that does not replace checking what a tool is about to edit.

Sources:

  • https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants

Source: https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants

We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.

Copied to clipboard. Paste it into your AI (ChatGPT, Claude, or your agent) to add the skill.