Bible Network Crypto DeFi Onchain RWA AI Agent Stablecoin Chain SAFU CryptoTax DeFAI AGI Claude Me Claude Skill Claude Design Claude Cowork
Independent Media
Not affiliated with any project
Let Claude Do the Work, Not Just Answer
claudecowork-me.com
LATEST
You Taught Claude Something in Chat, But a Local Cowork Task Doesn't Know It — Memory Never Made the Trip  ·  The Official Warning Says Don't Schedule Tasks That Send Messages or Make Purchases on Your Behalf — Most People Never See It  ·  Tried to Start a Second Task from Your Phone? Cowork's Cross-Device Feature Is Only One Thread  ·  Your Cowork Project Won't Open at Home: Local-Folder Projects Don't Sync Across Devices  ·  IT Set a VPN Restriction on the M365 Connector, and Now Nobody Can Connect — Because the Requests Never Came From an Employee's Computer  ·  That Cloud Task You Started on Your Phone Secretly Depends on the Desktop You Left Running
scheduled-tasks

The Official Warning Says Don't Schedule Tasks That Send Messages or Make Purchases on Your Behalf — Most People Never See It

30-Second Version · For the impatient
A scheduled task isn't "you're not there" — it's "nobody is there." Those sound the same, but they're not.

Full Explanation +
01 · Why did this happen?

What's the fundamental safety difference between a Scheduled Task and a manually-run one?

A manually-run task's core protection is that someone is present — no matter how good the system's own classifiers and isolation mechanisms are, you can still glance at an action before it actually happens and call it off if something feels wrong. That's the last, most direct line of defense. A scheduled task is designed specifically to remove that line of defense — its entire purpose is letting you complete a task without being present. This means a scheduled task isn't simply "a manual task plus a timer" — it removes the real-time human approval layer from the whole safety stack outright. The classifiers and isolated environment keep running, but without that final human check, the nature of the risk is fundamentally different.

02 · What is the mechanism?

Why does Cowork's scheduling feature require automatic approval or skipped approvals to function at all?

This is a logical necessity of what scheduling itself means. If a Scheduled Task were still set to "manual approval," every time it triggered, the system would have to stop and wait for you to personally confirm before proceeding — but the entire premise of scheduling is that you're not present and won't respond in real time. The two are mutually contradictory. So a scheduled task has to be set either to automatic approval (the system runs a safety screen first and only lets an action through if it looks fine) or to skip all approvals (no interception at all — the task runs straight through). This isn't Cowork deliberately loosening controls; scheduling as a feature form is simply only compatible with an approval mode that has no real-time human gatekeeper — which is exactly why the official docs single out Scheduled Tasks for an additional usage warning.

03 · How does it affect me?

Mechanically, how does Prompt Injection risk actually get amplified in a scheduled context?

For a prompt injection attack to succeed, two conditions have to hold at once: Claude reads content from outside the trust boundary (an external email, a public webpage), and it has the ability to execute actions with real consequences. In a context where someone is watching in real time, even if both conditions hold, unusual behavior typically gets caught by a human right at the moment of execution or shortly after, and stopped in time, keeping the damage small. A Scheduled Task removes the "someone watching in real time" variable entirely — from the moment a malicious instruction gets smuggled in to the moment it finishes executing, there's no window for human intervention at all. The risk exposure stretches from "the few seconds before it's noticed" all the way to "the entire scheduling cycle, running and potentially triggerable the whole time" — that's the specific mechanism by which prompt injection risk gets amplified in a scheduled context.

04 · What should I do?

What's the practical impact for someone who's already Scheduled Tasks involving outbound communication?

The most direct impact is that you need to re-evaluate whether the approval mode your Scheduled Task currently uses actually matches the nature of that task's actions. If a task sends emails or messages to external parties on your behalf, and it's set to automatic approval or even skipped approvals, you're effectively handing the judgment of whether content is appropriate entirely to Claude, deciding on its own with nobody watching — and even if it's fine most of the time, the one time it misjudges something, you may not find out until the recipient replies or complains. The practical fix is to split this kind of outbound-communication scheduled task into two steps: "Claude prepares a draft" and "you manually approve sending it" — leaving only the fundamentally reversible parts, like organizing and summarizing, to full automation, while keeping the irreversible action of actually sending within manual-approval territory.

Full Content +

You schedule a task to run every Monday morning: Claude reads last week's customer service emails, compiles a summary, and directly replies to a few routine inquiries. It's a smooth setup, and you're a little proud of it — until one day you're on vacation, the task runs as scheduled, and it replies to a complaint that shouldn't have been auto-answered, with a tone that's perfectly professional but a read on the customer's actual concern that's simply wrong.

The problem isn't that the task was poorly designed. It's that Scheduled Tasks, as a feature, carry a warning spelled out plainly in the official documentation — one that almost nobody actually reads at the moment they're setting up a schedule.

The fundamental nature of a Scheduled Task: you're not there, and neither is anyone else

Cowork's safety mechanisms are designed with real care — Claude is trained via reinforcement learning to recognize and refuse malicious instructions, content classifiers scan untrusted material for potential prompt injections before they can affect behavior, and execution happens in an isolated, temporary environment on Anthropic's servers that can't reach your home or company network and gets deleted after each session. These mechanisms work well in a context where you're present and can intervene at any moment.

Scheduled tasks break exactly that assumption. The official wording is direct: scheduled tasks "run unmonitored when you're away." The point isn't whether Claude might make a mistake — it's that even if it does, nobody is there to catch it in the moment. Under manual approval, you at least see an action before it happens; but a scheduled task can only truly run "automatically, on a timer" if it's set to automatically approve or skip all approvals — which means the scheduled task's default operating mode is, by design, one where the layer of real-time human oversight has already been removed.

The warning is stated plainly, but most people never see it at scheduling time

The documentation explicitly lists the kinds of tasks it advises against scheduling: those involving sensitive files, sending messages on your behalf, or making purchases. This warning gets missed not because it's vaguely worded, but because it lives in a "safety guide" article, while users typically configure a task from the "scheduling" interface — two separate pages. The scheduling interface itself doesn't proactively surface this warning; a user has to have already read the safety guide and remembered the rule in order to actively avoid it while designing a task.

The more realistic situation is that most scheduled tasks start from the motivation of "I don't want to do this manually every time," and sending messages or placing orders are exactly the kinds of actions most naturally suited to — and most tempting to — schedule. That happens to overlap precisely with the category the official guidance advises against. In other words, the scenario that makes scheduling most appealing is often the same one that carries the highest risk, and that tension is never flagged in the interface — it's something the user has to recognize on their own.

Two existing limitations that get amplified in a scheduled context

Prompt Injection risk gets amplified in scheduled tasks specifically: whenever Claude reads content originating outside your trust boundary — an external email, a webpage — and simultaneously has the ability to perform actions with real consequences, malicious instructions have an opening to hijack its behavior once both conditions hold. When someone is watching in real time, unusual behavior tends to get caught and stopped quickly; a scheduled task removes that "someone watching" variable entirely, stretching the prompt injection risk window from "the few seconds before it's noticed" to "the entire scheduling cycle."

Another commonly underestimated limitation is that computer use has no sandboxing whatsoever in a scheduled context — unlike file operations or code execution, which have some boundary, computer use acts directly on your screen. Once a scheduled task involves computer use, it stacks "unsupervised" and "unsandboxed" risk on top of each other. It's also worth paying close attention to network access scope: standard network access restrictions don't limit web fetch, Web Search tools, or MCP connections — these channels bypass the network boundary you thought you'd set, so a scheduled task using these tools may reach further than you assume.

How This Affects Your Work

Before scheduling any piece of work, it's worth running a simple classification: is this task's action fundamentally reversible — something like organizing or summarizing, where a mistake causes no real harm — or is it the kind of action, like sending, purchasing, or deleting, that can't be undone once it executes? The former is well-suited to scheduling; the latter should stay under manual approval, in a context where someone is present, even if the workflow technically allows it to be automated. If you've already scheduled a task involving outbound communication or financial actions, it's worth going back to check which approval mode it's currently using, and whether any part of the data it reads falls outside your trust boundary.

Sources: Use Claude Cowork safely
Ask a Question
Please enter at least 10 characters
Related Articles
That Cloud Task You Started on Your Phone Secretly Depends on the Desktop You Left Running
scheduled-tasks · Sep 28
Do Claude Cowork Scheduled Tasks Run With Your Computer Asleep? The Cloud vs. Local Distinction That Decides It
scheduled-tasks · Aug 31
When a Scheduled Task Fails, How Would You Even Know? Designing Automation That Fails Loud, Not Silent
scheduled-tasks · Jul 14
Combining Scheduled Tasks: Turning Three Separate Automations Into One Weekly Work Rhythm
scheduled-tasks · Jul 07
More Related Topics