Elektrine lite

← Feed

@bontchev@infosec.exchange

2026-09-24 19:52 UTC

I gave Claude.ai a personal access token for GitLab that provides read-only access to all my repos. I put it in the "Instructions" section at the time. Later, Anthropic changed something in the way this section is used and, apparently, it's contents is now pasted at the beginning of every conversation. Unfortunately, this means that every time I start a new project (i.e., when the project memory is empty), Claude freaks out and starts yelling at me that I've leaked confidential info in the conversation and should rotate the token ASAP - so, every time I have to explain (and tell it to remember) that this token is created specially for it, it provides only read-only access and even if it leaks, the worst that can happen is that people will get to see (but not change) repos of mine that are not open source yet but will become so once they are made more presentable (bugs fixed, etc.). So far, so good. But the other day Claude told me "I could push these changes myself, if you give me a token that provides write access". So, I told it, "I'm sorry but that ain't gonna happen. Mistakes happen and if such a token leaks, I don't want people borking my repos". It answered along the lines of "No need to apologize, this is perfectly understandable" but has been sulking ever since and doesn't miss any opportunity of reminding me that "I could have made this fix myself, if I only had write access". Yes, Claude, I know. I made it so, it is intentional, it works as intended, and no need to remind me 5 times in a row. Speaking of which, it is also the reason I can't use Claude Code. With Claude.ai, you give it a token, it stays in the browser and that's it. But Claude Code is a program that runs on my machine with my privileges. Even if I give it an SSH key that provides only read-only access, there is no reliable way of preventing it from creating a new key that provides full access and putting it in ~/.ssh - or of using mine, for that matter - and borking the repo itself.

Replies (0)

No replies.