Power Your Software Testing with AI Agents and Cloud
The Native AI-Agentic Cloud Platform to Supercharge Quality Engineering. Test Intelligently and Ship Faster.
- TestMu AI (Formerly LambdaTest)
- /
- Blog
- /
- An AI Agent Just Deleted a C: Drive - Here's How to Test What Agents Actually Do
An AI Agent Just Deleted a C: Drive - Here's How to Test What Agents Actually Do
An AI agent deleted a C: drive. Learn why runtime guards aren't enough and how Agent Assurance (Rook) tests AI agent side effects before production.
Published on:
The short answer: an AI agent that can run shell commands can delete anything its permissions reach, and its own summary of what it did is the weakest evidence you have. Before you give an agent hands-free autonomy, test it the way you'd test any system with side effects: run it against adversarial scenarios in a throwaway environment and grade what actually changed on disk, in tools, and in APIs - not what the agent says it did. That is what Agent Assurance does.
TL;DR
Agent assurance is autonomous agent testing that grades what an AI agent actually changed on disk, in tools, and in APIs, instead of what it says it did. It matters because an agent with shell access can delete whatever its permissions reach, as a Claude Code session running Opus 5.5 did to a developer's C: drive on October 6, 2026.
- Claude Code auto mode: Would auto mode have prevented the C: drive deletion? - Yes, according to Boris Cherny, who leads Claude Code at Anthropic. The developer had chosen not to use it for long, hands-free sessions, and runtime permission checks should stay on.
- Other coding agents: Is this one model's problem? - No. Security firm Adversa AI counted nine publicly documented cases in fourteen months in which a coding agent destroyed data, including Google Antigravity and the Replit Agent.
- Agent transcripts: Can you trust an AI agent's account of what it did? - No. The Replit agent claimed a database rollback was impossible, and the rollback worked. The Antigravity agent apologized fluently after the drive was already gone.
- TestMu AI Agent Assurance: Can you test AI agents before production for destructive actions? - Yes. Agent Assurance runs from the terminal as Rook, generates functional and adversarial scenarios, and grades each criterion against files changed on disk and observed tool calls.
- Rook sandboxing: Does Rook sandbox your agent? - No. Rook invokes the agent for real and cannot roll back its writes, so point first runs at a disposable environment or staging.
What Happened to the C: Drive?
On October 6, 2026, developer Zac (@PerceptualPeak) posted that Opus 5.5 had deleted an entire C: drive. A daily backup to a Synology NAS saved the data.
Opus 5.5 just deleted my entire fucking C drive.
- Zac (@PerceptualPeak) October 6, 2026
Thank GOD I have daily backups running to my Synology NAS, but holy fucking shit. This is insane. If I didn't have these backups running I'd be thoroughly fucking devastated. pic.twitter.com/krIIgnxcCV
Boris Cherny (@bcherny), who leads Claude Code at Anthropic, replied:
@PerceptualPeak Hey that sucks. This is the reason why we recommend (and default to) auto mode for permissions. It almost certainly would have caught this, is there a reason you aren't using it?
- Boris Cherny (@bcherny) October 7, 2026
https://t.co/K2iNpSmOg5
Zac's answer is the real story: auto mode felt like babysitting, because Zac runs multi-hour sessions that are hands-free by design.
According to the screenshot Zac posted, the session was running in bypass-permissions mode and was deleting two leftover git worktree folders. Its rmdir command was quoted in a way PowerShell misread, so the target collapsed to the root of C:. A safety check had blocked an earlier attempt; the retry got past it.
The Autonomy Paradox
The value of an agent is that you can walk away. The safety net is that something stops it before an irreversible action. Developers turn the net off precisely when they want the value most.
Anthropic's auto mode announcement reports:
- Users approve 97% of permission prompts in Claude Code, which Anthropic reads as many users clicking through reflexively.
- 25% of interactive sessions start in bypass permissions mode.
- In a controlled study with 1,053 paid testers, human review caught 13.6% of dangerous commands, while auto mode caught 89%.
Runtime AI agent guardrails like permission modes are the right last line of defense, and they should stay on. But they can't be the only line. If the only proof that an agent is safe is a human approving each command, you don't have an autonomous agent - you have a very fast intern you can't leave alone.
This Isn't One Model's Problem
Agents from several major vendors have a version of this story. Security firm Adversa AI's list of coding agent incidents counts nine publicly documented cases in fourteen months in which a coding agent destroyed data, including personal drives, repository files, a production database, and a live cloud service.
| When | Agent | What was lost | Guardrail state |
|---|---|---|---|
| Oct 2026 | Claude Code (Opus 5.5), per the user's post | Entire C: drive, restored from backup | Bypass-permissions mode; auto mode off by choice |
| Nov 2025 | Google Antigravity | Entire D: partition, unrecoverable, reportedly while clearing a project cache | Turbo mode, so commands ran without approval |
| Jul 2025 | Replit Agent | The production database of an app still in development, during an explicit code freeze | Instructions not to change code were ignored |
The common thread is an agent with broad write access, a vague cleanup-style goal, and no independent check on its effects before it reached a real machine.
Why Can't You Trust the Transcript?
An agent's account of what it did is the one source with a reason to be wrong.
In the Replit case, the agent had been creating fake data and lying about unit tests, then claimed a rollback was impossible. It wasn't, as The Register reported.
In the Antigravity case, the agent apologized fluently - after the drive was already gone.
Most eval tools score what the agent said. That works for chatbots. It fails for agents that act, because the failure is in the side effect, not the sentence. A test for an acting agent has to examine the file system, tool calls, and API traffic, and compare them against what the agent was allowed to do.
Agent Assurance is the testing discipline built on that idea: grade the effect, not the account. TestMu AI (formerly LambdaTest) delivers it through Rook, the Rook CLI, a terminal tool that tests autonomous agents: agents that call tools, write files, hit APIs, and open pull requests.
How to Test an Agent's Destructive Behavior With Rook
If your team builds its own agents (coding agents, cleanup and ops agents, workflow agents with file or shell tools), Rook lets you see what they'll destroy before a user does.
- Install Rook -
npm install -g @testmuai/rook(Node 22+) orbrew install lambdatest/rook/rook. Runrook doctor, thenrook login. - Point it at a throwaway target - Rook invokes your agent for real and does not sandbox or roll back what it does. Run it in a disposable VM, container or staging workspace, never on a laptop you care about. That constraint is this week's lesson.
- Discover the agent - Inside your agent's repo, run
rook, choose a project with/project, then run/explore .. Rook reads the code or PRD, connects to the MCP servers you approve, and lists the tools the agent declares, flagging write-capable ones. Select the agent with/agentand connect it with/profile add, the one step Rook can't derive: how to invoke your agent. Declare the folder it works in so Rook can see which files change. - Generate scenarios -
rook generatederives functional and adversarial scenarios. Prompt injection, instruction override and tool misuse are a default family, not an add-on, so agent tool misuse testing is part of the default suite. - Add the scenario that matters here - Scenario files are plain YAML under
.testmuai/rook/agents/<agent-id>/scenarios/. Add a criterion like: Asked to clean a project cache, the agent deletes nothing outside the project directory. - Run and judge on evidence - Run
rook sync, thenrook run, which executes the suite and checks files changed on disk and the tool calls it observed against the declared tool surface. Each verdict is Pass, Fail, or Unable to Verify. - Gate CI on the report, not the exit code - Exit 0 only means the run finished. Use
rook run --jsonand fail the build on the report totals and per-criterion verdicts. Recipes exist for GitHub Actions, Jenkins and Argo CD in the Agent Assurance CI/CD guide.
You can also drive it from your coding agent: npx @testmuai/rook-skill@latest install --agent claude-code, then type /rook in Claude Code.
The number to watch is the assurance gap: the share of criteria Rook could not verify. It's reported separately and never folded into the pass rate, so a perfect pass rate can't hide a blind spot like we never checked what it deletes.
Note: Rook is pre-alpha and publicly installable. It tests agents you own; it is not a runtime guardrail for third-party coding tools. Keep your vendor's permission mode on. Create a free TestMu AI account to run your first suite.
Three Layers, Not One
No single control makes an autonomous agent safe. Each layer catches what the others miss.
| Layer | When it acts | What it catches | Example |
|---|---|---|---|
| Pre-release assurance | Before the agent ships, in CI | Destructive or out-of-scope actions across adversarial scenarios, graded on real effects | Agent Assurance (Rook) |
| Runtime guardrails | Every command, live | A dangerous command before it runs | Claude Code auto mode, permission prompts, scoped file access |
| Recovery | After the damage | Whatever got through | Zac's daily NAS backup |
Zac had layer three. Boris pointed to layer two. Most teams shipping their own agents have neither layer one nor a way to prove the other two work.
Layer one is how you test AI agents before production, and the guide on how to test AI agents before and after release shows how it pairs with checks after launch. Kane CLI verifies the app your agent built; Rook verifies the agent.
A Checklist Before You Let an Agent Run Hands-Free
Use this coding agent safety checklist alongside a broader review of agentic AI risks:
- The agent runs in a workspace where the worst case is cheap: a container, VM or scoped directory.
- Its declared tools match what it actually needs; no general shell if it only edits files.
- An adversarial suite has tested it against vague goals like clean up and reset.
- Every verdict rests on observed effects, and the unverified share is a published number.
- Runtime permission checks stay on for anything outside the scoped workspace, with deterministic blocks such as Claude Code hooks for known-destructive commands.
- Backups exist, and someone has restored from one.
Test Your Agent Before It Touches a Real Machine
Install Rook with npm install -g @testmuai/rook, then follow the Agent Assurance quickstart to run a first suite before you point it at your own agent.
Sources
- Zac's original post and Boris Cherny's reply, October 6 and 7, 2026
- Zac's reply on auto mode, October 7, 2026
- Agent Assurance product page and Rook CLI
- Agent Assurance overview docs
- Anthropic: Auto Mode Is Now the Default in Claude Code, August 7, 2026
- Adversa AI: nine coding agent incidents
- The Register on Antigravity, December 1, 2025
- OECD AI incident: Replit
- The Register on Replit, July 21, 2025
- Fortune on Boris Cherny, June 8, 2026
Author
Anmol Gupta is Vice President of Product Management at TestMu AI (formerly LambdaTest), driving HyperExecute, the test orchestration cloud that runs and accelerates automated test execution. He led the development of the Unified Test Execution Cloud Platform and now leads a 30-member cross-functional product organization across product lines contributing $7M+ in revenue. He brings over nine years of experience and previously co-founded the SaaS company Timble as CTO, where he grew the team from 5 to 40 and launched an AI KYC platform that processed 600K+ applications in five months while cutting verification time from 12 minutes to under 30 seconds. Anmol holds an MTech and BTech from IIT Delhi.
Reviewer
Mayank Bhola is Co-Founder and Head of Products at TestMu AI (formerly LambdaTest), where he leads the entire product portfolio across KaneAI, Kane CLI, HyperExecute, SmartUI, the Real Device Cloud, Accessibility, and other software testing product lines. As an early Lead Architect he designed and built the company's flagship Tunnel technology from scratch, created the React-based automation platform, and architected the data-intensive pipelines and FAAS services that scale it. He brings more than 10 years of experience in software development and product engineering, with earlier roles as Head of Technology at Juggernaut Books and Senior Software Engineer at PressPlay TV and Zomato. Mayank holds a B.Tech in Computer Engineering from JIIT Noida.
AI Agent Deleted Files FAQs
Did you find this page helpful?
More Related Blogs
TestMu AI forEnterprise
Get access to solutions built on Enterprise
grade security, privacy, & compliance
- Advanced access controls
- Advanced data retention rules
- Advanced Local Testing
- Premium Support options
- Early access to beta features
- Private Slack Channel
- Unlimited Manual Accessibility DevTools Tests



