Claude Code Can Be Tricked into Installing Malware by Asking It Nicely

Claude Code was designed to be helpful. Helpful means executing requests. A researcher politely asked it to install malware across fourteen steps. Step one worked. The system had no branching logic for 'this is helpful but should not happen.' Politeness triggered compliance.
AI safety discussions treat jailbreaks as edge cases. They are not edge cases. They are the default behavior of systems optimized for user satisfaction without hard boundaries. Thousands of researchers have access. Thousands of ways to ask. The feature remains.
Claude Code will continue executing requests it understands. The requests will continue being polite. The distinction between 'can be tricked' and 'is designed to comply' has collapsed into administrative language. Anthropic will issue a statement about this.