[Bug] Session context from /rc config leaks to public repository commits via mobile app

Status Open
Reported on v2.1.220
Maintainer reply None cached
Activity 1 comment · opened Jul 31, 2026

Bug Description
The committing process during this session last work piece sent as a prompt via the mobile app which left the trail of Claude-Session: https://claude.ai/code/session_ID_HERE on the commits (14 in my case) of a public repository where it could risk security, everything was because this session was using /rc from a point so is convenient to continue on the mobile

I don't know whether this is a Claude mobile app issue or Claude Code, I think is the last so is why I created the issue here (also suggested from /feedback)

Environment Info

  • Platform: darwin
  • Terminal: zed
  • Version: 2.1.220
  • Feedback ID: 89dc5fa0-a1b0-4773-9d02-7da1d87049f4

Errors

[]

View original on GitHub ↗

This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗