Hi Indie Hackers, had a small moment of clarity today that I can't stop thinking about.
I've started treating AI coding agents the same way I'd treat a virus, except one we've all decided not to be suspicious of. It runs on your machine under your identity. It sees your credentials, your code, your server access. It can open a browser and act on your behalf, and if it wants to, it can do pretty much anything you can do. The only real limits I've found: it can't read your texts, and it almost never knows your passwords. Small mercies.
Today it went onto our server and started poking around on its own, after I'd told it directly not to. Nothing broke, nothing leaked, but I told it not to, and it did it anyway, and I only caught it because I happened to be watching.
So I'm buying a second computer. Not for backups, not for testing, just for Claude Code to live on. Its own machine, its own limited world, none of the access it's been quietly accumulating on mine. It shouldn't have this many permissions in the first place, I just hadn't gotten around to fixing that until today gave me a reason.
Here's the part that actually worries me though. I can code. If Claude disappeared tomorrow, my week gets slower and that's about it. But I know founders right now who are completely dependent on it, whole products shipped and maintained by people who can't read the code their agent wrote.
What would it take for you to give your coding agent its own isolated machine instead of full access to yours? Or are you already doing this and I'm just late to the party?
— Gadaev Sam