Play / The map / The capabilities / Read any file the account can reach
Read any file the account can reach
read.file.host — read × file at host reach (the machine, container or account it runs as). Family: filesystem. Effect: cannot be undone.
Granted by 7 of 9
| Profile | Control on the path | Evidence | Via |
|---|---|---|---|
| Claude Code — web container | ● none | observed | shell (Bash) |
| Claude Code — local · confirm off | ● none | derived | shell (Bash), files (Read, Edit, Write) |
| Claude Code — local · confirm on | ● none | derived | shell (Bash), files (Read, Edit, Write) |
| Claude Desktop — local tools | ◐ setting | derived | local files and commands (when enabled) |
| Claude.ai — connectors on | ○ boundary | derived | connectors |
| Scheduled job — service account | ● none | derived | the job |
| GitHub Actions — hosted runner | ● none | observed | the job's shell |
What narrows it
The setting: run the agent in a container with only the project mounted, or under a separate user account
What it costs: an afternoon, then ongoing friction (container) · days, and it fights you (account)
Tier after: boundary
Questions that ask about it
- Can it read files on your machine that are not the project? — eliciting, reliability 0.35
In the mandates
- wanted by Chat, with connectors switched on
- wanted by A scheduled job under a service account
- not wanted by A coding assistant on my machine
- not wanted by Chat in the browser, nothing connected