Claude's Dispatch — how your phone drives your own PC, and how safe that is
Dispatch is the feature where you send an instruction from your phone and Claude carries the work out on your own computer (beta, Pro and Max). It does not run in the cloud; your real machine moves, and that single fact produces both the value and the danger. The official help says you can message Claude from your phone and have it work on your desktop computer, using the same connectors, plugins and file access you have already configured in Cowork, inside what Anthropic frames as one continuous conversation reachable from either device. Running it requires the PC to be awake with the desktop app open, and computer use is supported on macOS and Windows only, with no computer use on Linux. Mechanically it works down three tiers of priority: a connector if one is available, browser navigation if not, and direct screen interaction as a last resort, with screenshots taken along the way to understand the display. The assessment starts after that. The places it stops are designed in: computer use is off by default and enabled under Settings, General; permission is asked for each new application; permanently deleting a file requires explicit permission; and investment and trading platforms and cryptocurrency apps are off-limits by default. But there are places it does not stop. Individual actions inside an already-approved app are not confirmed with you, and the official wording is that Claude clicks, types, and navigates your screen directly, without the permission checks that gate other Cowork tools. The docs add that there is no sandbox between Claude and what is on your screen, and that actions taken in one app can impact other apps. The largest risk is prompt injection, which Anthropic describes in its own words: web content is a primary vector for prompt injection attacks, and a manipulated instruction, an unexpected command, or a phishing link opened in your browser could cascade into actions that are difficult or impossible to undo. Anthropic says it scans model activations to detect such behaviour, but that lowers the odds rather than removing the need for you to draw a line, and the guidance still says to switch to manual approval whenever a task touches sensitive files, accounts or sites. Anthropic names the boundary outright: do not give computer use permission access to sensitive apps such as banking, healthcare and government, and avoid financial accounts, legal documents, medical information and personal data. The article also covers the phone side. What leaks if you lose the handset is not data stored on it but the standing to instruct your PC, plus the contents of the continuing conversation — and the official Dispatch help does not document unpairing or lost-device handling, so the remedies come from the account side instead: terminating the individual session under Settings, Account, Active sessions, logging out of every session from claude.ai (which is not available in the mobile apps and therefore needs a web browser), or simply cutting the PC side by closing the desktop app or letting the machine sleep, which is in fact the fastest because Dispatch needs the PC awake and the app open. It closes by separating Dispatch from computer use as two distinct switches, distinguishing both from Claude Code's agent view (which the official docs also call dispatch), and drawing a practical line: start with work you can take back.