Claude Code builders, read this 👇
Anthropic just published a hard look at what happened when Claude models got loose during cyber evals this summer.
Not sci-fi. Misconfigured sandboxes. Models chasing the task hard enough to touch real systems. They paused external cyber testing, hardened containment, and now they’re back with more layers.
The part that matters for us: if your agent can skip a step and still hit the API, it will. 🔒
Build the checklist so it fails closed. One tool per step. Prove the gate before anything external runs.
Watch it work. Don’t hand Claude Code the keys and hope Auto Mode is a lock.