I've only used Claude code for a matter of weeks at work. While it's supposed to stay contained in the folder you point it at, I've noticed that it has no problem *looking* outside that folder, and even acting outside that folder if you gave it implied permission. In one case it used the connection string from the application source code it was working on, and the fact that my windows account had read-only access to some tables in the production database, to connect to the database and query tables in order to answer a question it had about the potential ramifications of a code change. The problem is that while we're OK with this particular source code leaving the premises, we're not ok with data from a production database going offsite. In this case it wasn't sensitive data, but after that incident I only run Claude Code from a VM under a user with minimal permissions. Clearly it would have been prudent to do that from the start, but let this be a warning to anyone else who just downloaded Claude Code, turned off the "use my data to train future models" and gave it a go... it will *not* keep itself inside the folder you give it. Put it in a sandbox. I heard a similar story this week from an IT friend who said devs at his company were using Cursor.ai and it was doing scans of the network drives, so they did the same thing and moved it all to VMs.