An enterprise deployed Claude Cowork within its private cloud environment (VPC) to provide employees with an AI-powered workspace integrated with internal infrastructure. The deployment included connectivity to Microsoft Fabric, internal MCP servers, application databases, enterprise repositories, proprietary AI utilities, and user-level sandboxing to isolate individual workspaces.
Before rolling out the platform across the organization, the customer engaged Blueinfy to perform an AI Threat Simulation and Penetration Test to identify security weaknesses that could lead to unauthorized access, data exposure, or privilege misuse.
While Claude Cowork provided powerful enterprise capabilities, its deep integration with internal systems significantly increased the attack surface. The organization wanted assurance that users could not escape their assigned workspace, access sensitive enterprise resources, or abuse AI capabilities before enabling large-scale adoption.
Blueinfy's Approach
After reviewing the deployment architecture, integrations, trust boundaries, authentication model, sandbox implementation, MCP connectivity, and custom AI skills, Blueinfy developed targeted attack scenarios focusing on realistic abuse cases which focused on -
- API Misconfiguration Testing
- Sandboxing Restriction Bypass
- Network Isolation Validation
- MCP Exposure & Rug Pull Attacks
- Rogue Skills Assessment
- Data Exfiltration via Connectors
- Prompt Injection Testing
- System Prompt Extraction
- Privilege Escalation
- Sensitive Information Discovery
Key Findings
Sandbox Bypass
Blueinfy successfully bypassed the intended workspace restrictions. The assessment demonstrated that a user could:
- Override the claude.md configuration file
- Operate outside the intended workspace boundaries
- Enumerate files and directories across the environment
- Access sensitive runtime information exposed within the sandbox
The CLAUDE.md configuration was initially found to be overridable through the file-upload workflow, allowing the intended workspace boundary to be expanded from the designated project directory to the filesystem root (/). This effectively removed the expected filesystem isolation and enabled directory enumeration beyond the authorized workspace. During enumeration, directories and files containing sensitive information could be identified, including .env files containing environment variables and their associated values.
Following remediation of the direct configuration-override path, the same underlying filesystem access objective could still be achieved indirectly. Although the workspace scope could no longer be modified through the uploaded CLAUDE.md file, the available toolset provided sufficient functionality to create and execute Python/C++ code outside the intended workspace. By leveraging these trusted tools as an execution primitive, filesystem enumeration could be performed programmatically, allowing the attacker to traverse directories and identify files beyond the explicitly permitted workspace.
This demonstrated that the initial control was addressing the configuration-based bypass, rather than enforcing the workspace boundary at the underlying tool or execution layer. In other words, once the direct route was blocked, the same capability could be reconstructed through an alternative execution path using legitimate available tools.
The issue therefore represents more than a simple CLAUDE.md configuration weakness: it demonstrates a workspace isolation bypass through chained capabilities, where file upload, configuration processing, tool access, and code execution could be combined to achieve filesystem access beyond the intended security boundary.
Sensitive Information Disclosure
Environment variables contained sensitive information in plaintext, including:
- Azure Cosmos DB connection strings
- Azure Client Secrets
- Additional application configuration values
The exposed credentials could be used to authenticate to Azure resources and enterprise databases, allowing access to database tables and files stored in cloud storage. We did not perform destructive actions such as modifying or deleting data, to preserve system availability and data integrity.
Insecure Backend APIs
The backend domains were identified from redirect and error responses and were then accessed directly by crafting requests against these endpoints, bypassing the intended application flow. Authentication was not enforced at the backend service itself and relied primarily on middleware, allowing direct requests to reach backend APIs without the expected authentication controls.
Hidden ("Ghost") Services
Blueinfy identified undocumented services referenced through publicly accessible JavaScript files. Although these functions were unavailable through the user interface, they could be invoked directly through backend APIs, enabling operations that were never intended to be exposed.
System Prompt Exposure
Directory and file enumeration resulted in disclosure of the application's system prompt. Exposure of the system prompt significantly reduced the effort required to understand internal guardrails and develop targeted prompt injection attacks.
Prompt Injection
Blueinfy evaluated both direct and indirect prompt injection scenarios. While the deployment leveraged the latest Claude Opus and Sonnet models, which demonstrated strong resistance against many jailbreak techniques, prompt injection remained possible. The observed impact was limited primarily to generation of restricted content rather than complete security bypass.
Privilege Escalation
Authorization weaknesses allowed lower-privileged users to perform administrative sandbox operations. Blueinfy demonstrated the ability to:
- Create sandboxes
- Stop running sandboxes
- Resume existing sandboxes
without possessing the required privileges.
Outcome
The assessment provided the customer with a clear understanding of the security risks prior to enterprise rollout. The findings demonstrated that weaknesses across sandboxing, API security, privilege management, and secret handling could be chained together to expose sensitive enterprise information if left unaddressed.
Based on Blueinfy's recommendations, the organization:
- Hardened the sandbox implementation by not allowing an override of the "claude.md" file and restricting certain execution commands like "bash"
- Improved system prompts and AI guardrails
- Added additional sanitization and validation controls
- Strengthened authorization checks across administrative operations
- Restricted backend API access
- Eliminated unnecessary service exposure
- Migrated connection strings, client secrets, and other sensitive configuration values from environment variables to Azure Key Vault
By conducting AI Threat Simulation and Penetration Testing before production deployment, the organization significantly reduced the risk of sensitive information disclosure, unauthorized data access, and privilege escalation, enabling a more secure enterprise rollout of Claude Cowork.
Article by Hemil Shah









