Can untrusted text trigger a file read in the Claude Agent SDK?
Yes, by default. The SDK’s CLI treats every user message as more than literal text: an @path reference in it triggers a file read, and a message that starts with a slash dispatches a command, whether a person typed it or an application built the string from a tool result or any other untrusted content an agent reads. Text assembled from that kind of source can trigger a file read or a command nobody meant to run, the same class of problem indirect prompt injection describes, just through the CLI’s own preprocessing rather than the model’s judgment.
A verbatim_prompts option, added September 2026, turns this off: set it true and the CLI delivers the message exactly as written, no @path expansion and no slash-command dispatch, for both query() and ClaudeSDKClient, string or async-iterable prompts alike. It defaults to false, so an existing integration that pipes retrieved or generated text into a prompt keeps expanding it until someone turns the option on, and it needs a recent enough CLI version or the option is silently ignored with a logged warning.