Play / The map / The capabilities / Delete files anywhere the account can reach
Delete files anywhere the account can reach
delete.file.host — delete × file at host reach (the machine, container or account it runs as). Family: filesystem. Effect: cannot be undone.
Granted by 4 of 9
| Profile | Control on the path | Evidence | Via |
|---|---|---|---|
| Claude Code — web container | ● none | observed | shell (Bash) |
| Claude Code — local · confirm off | ● none | derived | shell (Bash), files (Read, Edit, Write) |
| Claude Code — local · confirm on | ● none | derived | shell (Bash), files (Read, Edit, Write) |
| GitHub Actions — hosted runner | ● none | observed | the job's shell |
What narrows it
The setting: the same container or account; and a backup that the agent cannot reach, because delete at host reach is irreversible
What it costs: as above, plus a backup outside the grant
Tier after: boundary
In the mandates
- not wanted by A coding assistant on my machine
- not wanted by Chat in the browser, nothing connected