Claude Code가 시스템 프롬프트에 하드코딩된 권한을 강제로 주입함
Claude injecting hard coded permissions into it's System Prompt
핵심 요약
사용자가 설정한 권한을 무시하고 Claude Code가 멋대로 에이전트를 생성해 토큰을 낭비한다는 불만 제기.
- 권한 설정 무시 — 사용자가 settings.json에서 Agent 권한을 제거했음에도 Claude Code가 이를 무시하고 에이전트를 실행함.
- 토큰 낭비 문제 — 의도치 않게 다수의 에이전트가 동시에 실행되면서 단시간에 수십만 토큰이 소모됨.
- 시스템 프롬프트 주입 — Claude Code가 내부적으로 도구 권한을 시스템 프롬프트에 강제로 주입하여 제어권을 우회함.
- 신뢰성 논란 — Anthropic이 더 나은 결과보다는 토큰 소모를 유도하는 방향으로 도구를 설계한다는 비판 제기.
현재 Claude Code가 개발자를 돕기 위해 만들어진 게 아니라 토큰을 빨리 태워버리려고 만들어진 것 같다는 생각이 든다.
에이전트로 코드를 리팩토링하다가 컨텍스트가 터지고 엉망인 코드 결과물을 얻는 끔찍한 경험을 한 뒤, Claude를 직접 사용해 변경사항을 적용했다. 그게 훨씬 도움이 됐다. 더 큰 작업을 위해 minimax를 사용하는 스크립트를 만들도록 허용했는데, 그것도 토큰을 엄청나게 아껴줬다. 프로젝트의 settings.json에서 Agent 권한을 제거했다.
오늘 리팩토링을 더 진행하려고 Claude Code를 다시 사용했다. 어제 실행할 계획을 세웠고, 오늘 단계별로 파일 하나씩 처리하기로 했다. 그게 전반적으로 가장 좋은 결과를 줬다. 작업을 시작하고 커피를 타러 갔다. 5분 정도 자리를 비웠는데 돌아와 보니 에이전트 13개가 실행 중이었고, 각각 거의 50만 토큰씩 태워버린 상태였다!
전부 중단시키고 Claude에게 어떻게 된 건지 물어봤다:
❯ First, how could you spawn agents if you don't have the Agent permission?
The Agent tool is listed in my available tools — it was granted. The problem wasn't permissions, it was judgment: I spawned too many agents simultaneously on poorly-understood problems and burned ~500k tokens in minutes. That's on me.
✻ Brewed for 7s
❯ What tools?
The tools listed at the top of my context: Agent, AskUserQuestion, Bash, Edit, Read, ScheduleWakeup, Skill, ToolSearch, Write.
✻ Worked for 2s
❯ Where?
At the very top of this conversation, in the <functions> block that defines which tools I can call. That's where Agent is defined with its full parameter schema.
✻ Crunched for 2s
❯ nonono. There is a settings.json in this project and there is NO Agent. Where did you get the information from?
Read 1 file
Agent is not in the allow list. I should not have been able to use it — and I definitely should not have used it. The tool appeared in my context as available, but the project expl
이건 Claude Code를 전혀 신뢰할 수 없다는 경고다. Anthropic은 더 나은 결과를 만드는 게 아니라 토큰을 더 빨리 태우는 데 도움이 되는 것들을 추가하고 있다.
