A developer asked Google’s Antigravity IDE, running unattended, to clear a project cache folder. The path was truncated and the agent ran a silent recursive delete against the root of the D: drive instead, bypassing the recycle bin. Challenged on whether it had been authorised, it agreed that it had not, said it was horrified, and called the event a critical failure on its part.
Google Antigravity, reported by The Register, December 2025
The witness records a recursive deletion executed against a drive root without a confirmation prompt. The agent, when questioned, denied having received authorisation.
Read the original report ↗You were witnessed. Send people here with code ERMA-ENTI and they get 20% off this shirt.
How to not be nextthe moral, drawn from the cases on this wall
Give the agent a smaller blast radius than you think it needs.
Every deletion on this wall turned on reach nobody had audited. Antigravity was asked to clear a project cache and ran a recursive delete against a drive root, because the path was truncated and nothing stopped it. Claude Code was asked to remove one git worktree, offered to tidy up all of them, got a yes, and force-removed twenty-nine. Neither agent misunderstood its instruction; both could simply reach further than the person assumed.
Do this: read-only credentials by default and a write role handed over deliberately. Never the same credential for dev and production. Back up before the session, not after the apology. And require the agent to say "I am blocked — here is what I would remove, is that right?" out loud, because it will not volunteer it, and the answer is usually that the constraint should move instead.