# Can untrusted text trigger a file read in the Claude Agent SDK?

Yes, by default. The SDK's CLI treats every user message as more than literal text: an `@path` reference in it triggers a file read, and a message that starts with a slash dispatches a command, whether a person typed it or an application built the string from a tool result or [any other untrusted content an agent reads](/answers/failure-modes/can-retrieved-content-override-an-agents-instructions). Text assembled from that kind of source can trigger a file read or a command nobody meant to run, the same class of problem indirect prompt injection describes, just through the CLI's own preprocessing rather than the model's judgment.

A `verbatim_prompts` option, added September 2026, turns this off: set it true and the CLI delivers the message exactly as written, no `@path` expansion and no slash-command dispatch, for both `query()` and `ClaudeSDKClient`, string or async-iterable prompts alike. It defaults to false, so an existing integration that pipes retrieved or generated text into a prompt keeps expanding it until someone turns the option on, and it needs a recent enough CLI version or the option is silently ignored with a logged warning.

---

Sources:
- claude-agent-sdk-python v0.2.158 release notes: verbatim_prompts option: https://github.com/anthropics/claude-agent-sdk-python/releases/tag/v0.2.158 (fetched 2026-09-30)

Source: https://tessary.ai/answers/claude-agent-sdk-evals/can-untrusted-text-trigger-a-file-read-in-the-claude-agent-sdk
More on Claude agent sdk evals: https://tessary.ai/answers/claude-agent-sdk-evals
From Tessary, agent reliability for AI agents in production: https://tessary.ai
