Can untrusted text trigger a file read in the Claude Agent SDK?

Yes, by default. The SDK’s CLI treats every user message as more than literal text: an @path reference in it triggers a file read, and a message that starts with a slash dispatches a command, whether a person typed it or an application built the string from a tool result or any other untrusted content an agent reads. Text assembled from that kind of source can trigger a file read or a command nobody meant to run, the same class of problem indirect prompt injection describes, just through the CLI’s own preprocessing rather than the model’s judgment.

A verbatim_prompts option, added September 2026, turns this off: set it true and the CLI delivers the message exactly as written, no @path expansion and no slash-command dispatch, for both query() and ClaudeSDKClient, string or async-iterable prompts alike. It defaults to false, so an existing integration that pipes retrieved or generated text into a prompt keeps expanding it until someone turns the option on, and it needs a recent enough CLI version or the option is silently ignored with a logged warning.

sources

keep reading

More on this.

Two ways to run Tessary.

Tessary is an open-source agent reliability platform. Cloud and self-hosted run the same workflow on the OpenTelemetry traces your agent already emits.

Tessary Cloud

We host it for you. Send your first trace with nothing to deploy and no model key.

what's includedper organization
traces
10,000 per calendar month
stored trace data
1 GB
retention
30 days
model credit
$10, one-time, for triage and root-cause analysis
credit card
not required

Self-hosted Tessary

Run the open-source code on your own infrastructure with one command. Add your own model key for triage and root-cause analysis.

Self-host Tessary for me by following https://github.com/tessaryai/tessary/blob/main/setup.md

docker compose -f oci://docker.io/tessaryai/tessary:compose up -d -y