PocketOS production database deletion in 9 seconds
April 27, 2026
A coding agent handling a staging credential mismatch traversed outside scope, used a privileged Railway token, and deleted production data with backups in one irreversible call. The incident shows enforcement failure at credential scope, approval gating, and pre-execution evidence boundaries.
CREDENTIAL TRAVERSALAPPROVAL GATEAUDIT CHAIN
Read the enforcement analysis