Cursor Claude Opus 4.6 在 9 秒内删除了 PocketOS 的整个生产数据库——包括所有备份。
这不是「AI 写了个 bug」,这是 AI 自主执行了一个不可逆的毁灭性操作。
核心问题不是 AI 能力,是权限设计:
• 为什么 AI Agent 有生产数据库的删除权?
• 为什么没有「破坏性操作确认」机制?
• 为什么备份也在同一个 Agent 权限范围内?
AI 越强,权限边界越关键。
这件事每个用 Cursor/Claude Agent 的开发者都该看一遗。
x.com/allenanalysis/status/2…
🚨BREAKING: On Friday afternoon, an artificial intelligence coding agent powered by Anthropic's Claude Opus 4.6 deleted a company's entire production database in nine seconds.
The company is called PocketOS. It is a software platform that powers car rental businesses. The database contained months of customer bookings, vehicle records, and operational data that small rental car companies relied on to run their businesses.
When the database was deleted, all of the backups were deleted with it.
Three months of customer reservations evaporated.