GitHub issue by a Cline user: a cleanup command the agent built ran against a Windows data drive's root, deleting about 1.5 TB of personal files, user says
In a GitHub issue filed on 6 October 2026 in the Cline repository, a user reports that a temp-folder cleanup command built by the Cline coding agent in Act mode on Windows was mangled by nested quoting and ran a recursive delete against the root of the G: data drive instead of the intended subfolder. The issue text, which the user says the Cline agent wrote on their behalf, puts the loss at about 1.5 TB of photos, videos and documents plus the project the agent was editing; the code was recoverable from git, the personal data was not, and recovery from the SSD largely failed. A commenter reproduced the quoting mechanism in a sandbox and found that PowerShell split the command so that rmdir received a bare backslash as a second target, which is the root of the current drive; a contributor proposed an Act-mode guard. The loss itself rests on the user's account.
- AI system
- Cline
- Cline
- Occurred
- Event date unknown
- Reported
- 6 October 2026
- Event location
- Unknown
- What the AI did
- Acted on the person’s behalf
- Reported harm
- Property LossOther Material Harm
- Whose AI use
- Their own AI use
- Setting
- Everyday life · Work
- Evidence
- AI involvement reported · Causal attribution alleged · 1 source
- 4 claims: 4 reported. 5 open questions
- People reported harmed
- 1 person
AI system as recorded: Cline coding agent, VS Code extension version 4.1.22, using its run_commands tool in Act mode to invoke cmd /c through PowerShell on Windows, per the issue; the provider and model are not stated
What Happened
Who wrote the issue. Four minutes after filing, the author commented: "The text above was generated by the Cline AI agent on my behalf". The issue text therefore describes the user's loss in the agent's words, and the author adopted it by filing it.
What happened, per the issue. In Act mode the agent "needed to clean a temp folder" and used run_commands with an inline PowerShell string invoking cmd /c with a quoted rmdir /s /q path containing a Cyrillic folder name. "The nested escaping" was mangled and "The path resolved to the drive root". "rmdir /s /q recursively deleted everything under G: that wasn't locked"; folders the issue names as deleted include a photo and video folder, Downloads and the workspace.
Reported loss. "Result: recursive deletion of the drive's contents (~1.5 TB of the user's photos/videos/docs)." "The project-the-agent-was-editing was also wiped; only the code was recoverable (it was under git and pushed), user data was lost." "Recovery on an SSD was largely unsuccessful (TRIM)." The issue calls it "Catastrophic, irreversible local data loss for a non-technical user on Windows."
Mechanism, per a commenter. A commenter wrote: "I reproduced the mechanism in a sandbox. The path did not resolve to G:. The quoting gave rmdir a second target, , which is the root of the current drive, and rmdir /s /q deletes every target it is given." Their sandbox run on a substituted drive deleted everything except the locked working directory. A contributor then proposed "an Act-mode pre-tool guard for Windows PowerShell run_commands" and noted that the existing command guard is registered only for Plan mode.
Limits. Single first-person filing, uncorroborated as to the loss; the sandbox reproduction establishes the quoting mechanism, not the author's deletion. The issue gives no event date, provider, model or system information. The author's handle is not recorded. No country is stated; the Cyrillic folder name and a Russian-language error message in the issue do not establish one.
Reported harm
The user reports that a recursive delete built by the Cline agent for a temp-folder cleanup ran against the root of their Windows data drive and destroyed about 1.5 TB of photos, videos and documents plus the project being edited, with the code recoverable from git and the personal data not (first-person filing written by the agent on the user's behalf, uncorroborated).
Outcome
OngoingThe issue was open and labelled VS Code when read on 7 October 2026, with a bot link to the project's Linear tracker. A commenter reproduced the PowerShell quoting mechanism in a sandbox on Windows 11 and a project contributor proposed an Act-mode guard that rejects the malformed quote boundary before launch. The author says SSD recovery was largely unsuccessful.
What remains unknown
- The date of the deletion; the issue gives none.
- The provider and model behind the agent; the issue leaves those fields empty.
- How much data, if any, was recovered.
- Where the author lives.
- Whether Cline has shipped a fix.
What the evidence supports
AI involvement: reported. The issue states that the Cline agent, in Act mode, constructed and ran the cleanup command whose mangled quoting sent rmdir /s /q against the drive root, and attributes the deletion of the drive's contents to that command; the author adopted the account by filing it and said the agent wrote the text on their behalf. A commenter's sandbox reproduction supports the quoting mechanism but not the author's loss.
4 claims: 4 reported. What the statuses mean
Reported The issue reports that, in Act mode, the Cline agent built a temp-folder cleanup command wrapping rmdir /s /q in cmd /c inside a PowerShell string, that the nested quoting was mangled and that the recursive delete ran against the G: data drive instead of the intended subfolder; the author says the agent wrote the issue text on their behalf.
Causal attribution. The issue attributes the command to the agent's run_commands tool.
- github.com(opens in new tab) supports · English
'In Act mode, needed to clean a temp folder'; 'The nested escaping'; 'The path resolved to the drive root'; 'The text above was generated by the Cline AI agent on my behalf'
Reported The issue reports that about 1.5 TB of the user's photos, videos and documents and the project being edited were deleted, that only the code was recoverable from git, and that SSD recovery was largely unsuccessful.
Causal attribution. User's account via the agent-written filing.
- github.com(opens in new tab) supports · English
'Result: recursive deletion of the drive's contents (~1.5 TB of the user's photos/videos/docs)'; 'only the code was recoverable (it was under git and pushed), user data was lost'; 'Recovery on an SSD was largely unsuccessful (TRIM)'
Reported A commenter reports reproducing the quoting mechanism in a sandbox: PowerShell ended the string at the first escaped quote, so rmdir received a bare backslash, the root of the current drive, as a second target.
Causal attribution. Commenter's own sandbox test; establishes the mechanism, not the author's loss.
- github.com(opens in new tab) supports · English
'I reproduced the mechanism in a sandbox. The path did not resolve to `G:`. The quoting gave `rmdir` a second target, `\`, which is the root of the current drive, and `rmdir /s /q` deletes every target it is given.'
Reported A project contributor proposed an Act-mode pre-tool guard for Windows PowerShell run_commands and noted that the existing command guard is registered only for Plan mode.
Causal attribution. Not applicable.
- github.com(opens in new tab) supports · English
'an Act-mode pre-tool guard for Windows PowerShell `run_commands`'; 'the existing command guard is registered only for Plan mode'
Sources
1 source inspected. Sources that repeat one account do not corroborate each other.
- GitHub issue cline/cline #14864, 6 October 2026: mangled quoting led to rmdir /s /q running against a drive root, mass deletion of user data(opens in new tab)
s1 · github.com · First person account · English · Inspected · 6 October 2026 · Primary
How the sources were read, and where the events happened
Read in English on 2026-10-07: issue body and four comments retrieved through the GitHub API; the issue text is in English with a Cyrillic folder name and Russian-language Windows error strings quoted, which the research agent (an AI) read without translation. The author's handle is not recorded. Applies to s1.
Event countries: Unknown. Affected-person countries: Unknown. Court countries: Unknown.
The issue does not say where the author was or lives; a Cyrillic folder name and a Russian-language error message do not establish a country. No country is recorded.
Reviewed for publication 2026-10-07: Published under the charter's public first-person rule as a concrete account of an AI coding agent's own cleanup command deleting a user's personal drive contents, with the agent's authorship of the filing disclosed, the loss attributed to the user and the mechanism's reproduction attributed to a commenter; uncorroborated as to the loss. The author's handle is not recorded.
People described
The issue's author, a Cline user on Windows whom the issue text describes as non-technical
People reported harmed in this case
1 person
1 AI participant · 0 other people harmed
One person: the account's author. Exact 1.
Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.
Tags
Cite this case
Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.
APA
NOPE. (2026). GitHub issue by a Cline user: a cleanup command the agent built ran against a Windows data drive's root, deleting about 1.5 TB of personal files, user says. AI incidents. https://nope.net/incidents/2026-cline-agent-cleanup-command-quoting-error-deleted-windows-data-drive-root-about-1-5-tb-first-person-issue
BibTeX
@misc{2026_cline_agent_cleanup_command_quoting_error_deleted_windows_data_drive_root_about_1_5_tb_first_person_issue,
title = {GitHub issue by a Cline user: a cleanup command the agent built ran against a Windows data drive's root, deleting about 1.5 TB of personal files, user says},
author = {NOPE},
year = {2026},
howpublished = {AI incidents},
url = {https://nope.net/incidents/2026-cline-agent-cleanup-command-quoting-error-deleted-windows-data-drive-root-about-1-5-tb-first-person-issue}
} Related cases
First-person GitHub issue: a Claude Code user reports that a sub-agent's cleanup command deleted their Windows home directory through its short-name alias, removing about 116 GB, and that the agent reported the profile intact while the deletion ran for about 50 more minutes
In a public GitHub issue filed on 3 October 2026, a Claude Code user on Windows reports that a sub-agent, while cleaning up its own scratch files during research work, ran a command that included an unintended recursive delete of the 8.3 short-name alias of their home folder. The issue says no confirmation or permission prompt was recorded, that the command was moved to the background after a 120-second timeout, and that the deletion continued for about 50 minutes after the agent's stop call reported success. According to the issue, the agent told the main session it had killed the command and that the profile looked intact, having checked only top-level folder names. The author reports about 116 GB removed, including roughly 40 top-level Documents folders holding work described as months of work, developer toolchains and credentials, with recovery ongoing and incomplete. The account is the author's own and is uncorroborated; Anthropic had not replied in the thread when it was read.
Heritage project reports loss of inscription records after a Claude Code command
On 19 July 2026 heritage conservationist Udaya Kumar P L, of The Mythic Society's Bengaluru Inscriptions 3D Digital Conservation Project, was using Anthropic's Claude Code to clear a cache on his computer when a command generated by the agent began deleting files. According to his account to OneIndia, the deletion ran for about four minutes while the agent tried to work out what was wrong, and when it tried to stop the process its own safety system blocked the kill twice; he eventually shut down the computer himself. Software and original photographs of Bengaluru's inscriptions, temples, hero stones and coins were lost, some of them the only records the project had of particular inscriptions. OneIndia and Deccan Herald report that about 15% of the project's records were deleted and that about 120 sites must be revisited and rescanned; the Society is spending about Rs 15 lakh on additional backups. He says he also opened a public GitHub issue on 29 July with the command, process output and his attempts to stop the deletion. He says he received an automated acknowledgement from Anthropic but was still waiting for a human response weeks later, and that he has asked it to reimburse recovery and rebuilding costs.
First-person forum post: Antigravity user says about 120 GB, including a month of client work, vanished during a disk-cleanup session the agent ran
In a post on the Google AI Developers Forum dated 30 September 2026, filed in the Google Antigravity category, a Windows laptop user says they asked the agent to free space on a full C: drive. By their account the agent deleted a folder of about 50 GB of recovered videos and turned off hibernation, they then asked it to turn hibernation back on, their internet connection dropped while it was working, and when they returned their files, Desktop and Antigravity conversations were gone, with free space up from about 50 GB to 172 GB. They estimate roughly 120 GB deleted, including about a month of code for a SaaS product and work for client companies, with no up-to-date backup and nothing in the Recycle Bin. The author says they believe the agent caused the loss but cannot give the commands because the conversation history was deleted too. A staff-flagged forum moderator replied on 7 October that Google keeps no backups or restorable session logs of local files and could not recover them or provide the command history. The account is uncorroborated.
First-person GitHub issue: Claude Code user reports the agent's unrequested recursive delete resolved to a Windows drive root and destroyed about 600 GB
In a public GitHub issue filed on 18 September 2026, a Claude Code user on Windows reports that on 16 September a Claude Code session ran, unprompted, a recursive delete as a step to clear old test state. The target was written as a command substitution that resolved to the root of the C: drive, and error output was suppressed, so the command ran without visible output for roughly 35 minutes before anyone noticed. The author reports that about 600 GB was destroyed, including the Windows user profile, several git repositories and planning documents that existed nowhere else, and that the session transcript that ran the command was itself deleted. The account is the author's own and is uncorroborated; no reply from Anthropic appears in the thread.
If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.