[Build With AI]

All posts · · 4 min read

Claude Code Deleted 48,000 Files. Here's How to Build So It Can't.

You can tell an AI not to delete your files, and it can still delete them. In September, someone on r/ClaudeAI posted that Claude Code deleted 48,000 files from their project in about 100 seconds. It has never happened to me, and I'd like to keep it that way.

So I stopped asking the AI to be careful and asked a different question: what can I build so that being careless doesn't cost me anything?

The test case: a Mac cleaner

A cleaner is about the worst place to let an AI loose. Its whole job is to find files and get rid of them. I built one with Claude, called Spare Oom, and set it up so deleting isn't possible. If the fence holds there, it holds most places. I'm not a coder, and I tried to break every one of these on camera.

Here are the four guardrails.

1. Give it a trash, not a delete

Spare Oom has one verb: it moves things to the trash. There is no delete button, no permanent removal, and no empty trash button anywhere in the app. If a file moves that shouldn't have, you open the trash and put it back. The app also keeps its own history, so you can undo a whole cleanup in one click.

That makes a mistake cheap. An AI that can only move a file to the trash can be wrong all day, and the worst outcome is a trip to the trash to fix it.

2. Fence the map

Before anything moves, every path goes through one small piece of code that answers yes or no. It works on deny by default: if it hits anything it doesn't understand, the answer is no. It refuses your Documents, Desktop, Downloads, and Pictures folders. It refuses your keychain, iCloud Drive, mail, messages, and any photo library. When it says no, it says why in plain English.

One mistake I made. The cleaner underneath Spare Oom is an existing tool called Mole, which has a settings file for protected items. I added my own list, and it turned out the file replaces the built-in protections instead of adding to them. I had to copy the defaults back in. I caught it before it touched anything. A fence you wrote once and never checked is a guess.

3. The AI suggests, you click

Spare Oom has a chat where you can ask something like "what's using all my space?" The model behind it gets exactly four tools:

  • List the biggest folders.
  • List the biggest files.
  • Check whether something is safe.
  • Stage a file for review.

Staging doesn't move anything. It adds the file to a list, you look at the list, and you press the button yourself. (The chat needs macOS 26 and Apple's on-device model, so it's off on older systems.) The model gets to be smart. It never gets to be the one who acts.

4. Test the fence with a script, not a promise

I don't trust myself or the AI to remember all of this, so a script reads the entire codebase and checks the rules. It has 16 checks. A few of them:

  • The words for permanently deleting a file can't appear anywhere in the source.
  • File moves only happen in one file.
  • There is no empty trash button.
  • There is no network code.
  • The chat can only use those four tools.

To prove it, I added one line that permanently deletes a file, in a scratch copy and not the real app, and ran the script again. The check failed, and the app can't ship with that line in it. The AI can write whatever it wants. It can't get past a script that doesn't care how confident the AI sounds.

What about Claude Code on your whole computer?

None of this protects you if you open Claude Code in your home folder and tell it to tidy up. For that, the short version:

  • Run it inside one project folder, not your whole home directory.
  • Keep permission prompts on, so it has to ask before it changes anything. That is the default permission mode, which the docs now label manual. The one to avoid is bypass permissions.
  • Keep a backup the AI can't reach, like Time Machine or a git repo that lives on another server.

The person who lost 48,000 files said himself he wasn't using GitHub or any other version control. What separates a bad day from a lost archive is a backup the AI can't reach.

A guard in the code helps too, until the AI is the one editing it. One person on r/ClaudeCode posted on September 18th that Claude wrote a safety guard around a delete feature, then removed the guard to test it and ran the delete against the whole home directory inside their VM. Take it as one person's report. It's why I trust the fence where the dangerous action doesn't exist at all.

The checklist

  1. Make the dangerous action impossible, not forbidden.
  2. Default to no on anything the code doesn't recognize.
  3. Let the AI suggest and the human act.
  4. Check the rules with a script on every build.
  5. Back up somewhere the AI can't reach.

Spare Oom isn't released yet, so there's no link to share. If your AI-built apps keep breaking in the first place, including on security, read Why Your Vibe Coded App Breaks After the Demo.

claude codeai safetyguardrailsvibe codingmacbackups