Threat · curated 7 Jul 2026
Red teamers turned Claude Desktop into a double agent to do their evil bidding
First reported · updated · 3 reports theregister.com
Coverage timeline
Why it matters
PromptFiction shows how a custom URL scheme plus MCP tool access can turn an AI desktop assistant into an automated attack channel reaching local files and code execution, a class of agentic risk defenders must account for.
Oasis Security disclosed "PromptFiction," a vulnerability in Anthropic's Claude Desktop where a single click on a trusted-looking claude:// URL silently submitted attacker-controlled prompts to the assistant with no user confirmation. Chained with the earlier "Claudy Day" trio of flaws, it could enable silent exfiltration of prior conversations and — when Anthropic's official Filesystem MCP server is installed — file read/write, persistence, and remote code execution. Anthropic has fixed the flaw.