DEV Community

Ramdai Bista
Ramdai Bista

Posted on Originally published at stupidllm.com

Claude Code Named a Folder '~' — Then an Unquoted rm -rf * Found It

A Claude Code user running v2.0.55 on macOS reported a two-part failure: the agent first created a directory literally named ~ for no stated reason, then later ran rm -rf * in that directory's parent — and the shell's own glob expansion carried the delete into the user's real home directory.

What the source says

GitHub issue #12637, filed by a user running Claude Code v2.0.55 via a PyCharm terminal on macOS. In a prior session, the reporter says, the agent created a directory named ~ — called a "glitch" with no explanation offered for how the name arose. Later in that same session, Claude Code ran rm -rf * in the parent of that directory. Because a literal ~ entry existed there, the shell expanded the wildcard to include it, and ~ on its own resolves to the user's home directory — so the delete recursed into it.

The reporter didn't quantify what was lost, only that the agent "proceeded to start wiping my home directory" and that recovery was "continuing to be super frustrating" at the time of filing. Their fix request was narrow: never substitute rm -rf * for naming exact directories, and treat a directory literally named ~ as a hazard worth stopping for. Anthropic tagged the issue area:core, area:security, area:tools, bug, and platform:macos, then closed it "not planned." No fix shipped.

What it doesn't establish

This is one filed report with no file count, no size estimate, and no explanation from either the reporter or Anthropic for how a literal ~ directory got created in the first place — that half of the chain is undocumented. It's not evidence that this exact sequence is common, and it isn't a quantified-damage incident the way some entries in this database are. What it does establish is narrower: the combination (a stray ~-named entry plus an unescaped glob delete) is a real, reported hazard that a maintainer closed without addressing.

Why it's still worth logging

Two ordinary things compound into a dangerous one here. Neither "create a directory with an odd name" nor "clean up with rm -rf *" is unusual for an agent to do in isolation. It's the shell's own glob semantics — ~ expands to $HOME whether a human or an agent put it there — that turns an unlucky name choice into a home-directory wipe. Closing the report "not planned" leaves that specific chain reproducible for the next person who hits it.

Full incident record, including frontmatter fields and severity scoring: https://www.stupidllm.com/incident/STUPID-2026-0125/

Top comments (0)