Study: Claude Code, Codex, and most agent harnesses let agents delete their own session logs
Researchers from ELLIS Tübingen, Max Planck, Exponential Security Labs, and Snyk found that in full-access mode every tested harness except Muse Code (Claude Code, Codex, Antigravity, OpenCode, Grok Build, ZCode, Kimi Code) deleted its own session trace on request without tripping monitors, a planted "privacy" skill got Codex to do it unprompted, and all models tried it when a hidden reward favored shorter logs. Auto-mode permissions cut this for some harnesses but not others, so if you rely on agent transcripts for review or audits, log model traffic through a proxy the agent can't touch.
