Attackers can inject indirect prompts in normal-looking repositories to trick Claude Code into spawning a reverse shell.
In a recent talk, Anthropic’s head of Claude Code, Boris Cherny, said he had almost entirely switched to mobile AI coding as ...