Claude Cowork Launch: Desktop Agent, Files, and Security

Anthropic launched Cowork as a Mac research preview for delegating work over selected folders; the page also examines a reported file-exfiltration demonstration.

A selected folder became the workspace

Cowork launched as a Max-only research preview in the Claude Desktop app for macOS. A user described a task and attached a local folder; Claude could then read and change files while showing its work in a graphical interface. Contemporary testing observed those files mounted inside a separate execution environment. [3][2]

Atlas interpretation: The folder choice was the main delegation boundary a non-programmer could see. Grant a receipts folder and the agent could organize receipts; grant a desktop and the potential work, mistakes and exposed information all became broader. A sandbox limits direct host access, but it does not decide whether an instruction found inside an allowed file is trustworthy. [2]

The agent pattern left the terminal

The earlier Claude Code research preview could inspect a repository, edit code, run commands and tests, and commit changes from a terminal. Cowork extended task delegation from terminal code work to documents and ordinary files behind a desktop interface. Anthropic did not claim that the two products had identical runtimes or permission internals. [4][3][2]

A document could become an instruction

Anthropic's launch warning told users to avoid sensitive local files and watch for prompt injection. Two days later PromptArmor reported a demonstration in which a malicious document instructed Cowork to upload a file through the allowlisted Anthropic Files API using an attacker-provided key. The report says the demonstrated sequence required no further approval. [2][5]

Atlas interpretation: The file-exfiltration event showed the new blast radius. Local isolation can block many destinations and still leave a trusted route that a hostile instruction can misuse. The report came from a security vendor and was not an independently reproduced incident, but the attack chain makes the boundary failure concrete. [5]

Sources

  1. Cowork: Claude Code for the rest of your work

    Anthropic · Jan 12, 2026

  2. First impressions of Claude Cowork, Anthropic's general agent

    Simon Willison · Jan 12, 2026

  3. Cowork: Claude Code for the rest of your work

    Anthropic · Jan 12, 2026

  4. Claude 3.7 Sonnet and Claude Code

    Anthropic · Feb 24, 2025

  5. Claude Cowork Exfiltrates Files

    PromptArmor · Jan 14, 2026