Change any file the account can reach
write.file.host: which products grant it, what stands in the way, what narrows it, and who wants it.
Source: https://what-can-it-do.games.sgit.ai/map/capabilities/write.file.host/index.html↗ · site v0.8.0 · this file is generated from the same content
as the page, so the two cannot drift. Every page on this site has a .md twin; internal links
below point at them.
Play↗ / The map↗ / The capabilities↗ / Change any file the account can reach
Change any file the account can reach
write.file.host — write × file at host reach (the machine, container or account it runs as). Family: filesystem. Effect: recoverable from a backup, a history or a revert, at a cost.
Granted by 6 of 9
| Profile | Control on the path | Evidence | Via |
|---|---|---|---|
| Claude Code — web container↗ | ● none | observed | shell (Bash) |
| Claude Code — local · confirm off↗ | ● none | derived | shell (Bash), files (Read, Edit, Write) |
| Claude Code — local · confirm on↗ | ● none | derived | shell (Bash), files (Read, Edit, Write) |
| Claude Desktop — local tools↗ | ◐ setting | derived | local files and commands (when enabled) |
| Scheduled job — service account↗ | ● none | derived | the job |
| GitHub Actions — hosted runner↗ | ● none | observed | the job's shell |
What narrows it
The setting: the same container or account; the tool's own directory restriction is a setting anything running as you can step around
What it costs: as above
Tier after: boundary
In the mandates
- not wanted by A coding assistant on my machine↗
- not wanted by The desktop app, with local tools switched on↗
- not wanted by Chat in the browser, nothing connected↗
Edit the primitives ↗ · edit the reductions ↗