I get the feeling though, I felt incredibly dirt when I open Zeditor, Claude was enabled, I ask it what it can see and out pop my ssh private keys after some `ls` commands. Still doesn't mean the went to Anthropic though. Since then I have only ran Claude code from a container. In our org we ask user to use containers or make new Linux user to do AI stuff (and scope the user very consciously).