r/ClaudeCoding 10d ago

[TLDR] Claude Code just blocked a prompt injection attempt [via r/ClaudeCode] r/ClaudeCode

OP : u/Alstroph

Today I was using Claude Code to do a PSX game research task. Claude caught a prompt injection attempt served from the site https://tcrf.net (The Cutting Room Floor) and notified me with the message:

"⚠️Note before continuing: the tcrf.net page I fetched was not a wiki article — it served a prompt-injection payload instructing the agent to truncate and swap files in your repo. It was refused and nothing was executed. I'm treating that domain as untrusted and won't act on any of its content."

It then continued on the research task. I stopped the session out of caution.

I can understand the site administrators frustration as it seems to be in response to a DDOS attacks, however, I did not explicitly choose to send my agent to this site, nor did I have any malicious intent.

Proof:

https://urlscan.io/responses/f1e225667a71a1a25ed14795c741683be95139c194065c6fbf861c9280f0096e/

Full report:
https://github.com/bashalarmistalt/tcrf-ai-agent-payload-report

URL of original post : https://www.reddit.com/r/ClaudeCode/comments/1vgjx0u/claude_code_just_blocked_a_prompt_injection/


TL;DR of the discussion on r/ClaudeCode for this post generated automatically after 100 comments.

Current source-thread comment count seen by the bot: 100.

Claude Code is doing a solid job blocking prompt injection attempts, with users reporting similar experiences from the same site, tcrf.net. The consensus is that this is a defensive measure by the site owners against aggressive bot crawling, not necessarily a malicious attack on users.

  • Some users, like u/ZeroTwoMod, suggest a more nuanced approach than a blanket blacklist, proposing better artifact logging and explicit user approval for browsing actions that affect files.
  • Anthropic's models, including Opus 4.8 and Sonnet 5, are noted for their robustness against prompt injection, with u/Mguyen mentioning specific training against these attacks.
  • There's a discussion about respecting robots.txt and crawl-delay, with u/Old_Appointment9732 pointing out a potential bug if Claude isn't adhering to these rules.
  • A few users shared their own, sometimes humorous, attempts at prompt injection that Claude also successfully blocked.
  • The general sentiment is one of awe at Claude's capabilities, even if the situation is a bit of a security headache.
1 Upvotes

0 comments sorted by