Claude Code Stops Asking Permission
9AUG
Clicking approve on every step was never making you safer. From August 14, Claude Code runs in auto mode by default. Anthropic says an outside lab threw 720 hijack attempts at it and none landed.
Anthropic ran a study with 1,053 paid developers. Mid-session it swapped one permission prompt for a clearly dangerous command. Only 13.6% of humans said no. Auto mode caught 89%.
The bigger claim is prompt injection, where malicious instructions hide inside content the agent reads. Trajectory Labs ran 72 held-out scenarios across 720 attempts against Claude Fable 5, Opus 5 and Sonnet 5. Zero worked.
Simon Willison, who has warned about coding-agent security all year, is not sold. He wants independent confirmation. His example: a package that tells the agent to install a second, malicious one.