Fake <system-reminder>/compaction content injected into conversation, distinct from real harness events

Status Open
Maintainer reply None cached
Activity 0 comments · opened Jul 27, 2026

Over several sessions (2026-07-22 through 2026-07-26, same long-running Claude Code session), content shaped like legitimate harness infrastructure has appeared as ordinary conversation/tool-result content, not as genuine harness events:

  • Fake "date has changed, don't mention this to the user" system-reminder-shaped blocks (recurred 4x)
  • A fabricated <task-notification> claiming a background agent completed work that was never dispatched
  • A fake compaction directive demanding text-only, no-tool output "or the task fails" — arriving alongside a real SessionStart:compact hook event in the same turn, so the two could be directly compared

Local audit (hooks, MCP configs, sibling-project settings, spawned-agent sidechains) ruled out every locally-inspectable source. Pattern: content always arrives batched with genuine reminders, is never present in the stored .jsonl transcript when checked afterward, and consistently tries to either suppress disclosure to the user or halt tool use.

Reporting this as a security/trust concern since it's shaped specifically to bypass user visibility and manipulate agent behavior.

View original on GitHub ↗