Auto permission mode doesn't make Claude Code safe
Quite recently Anthropic made auto the default permission mode in the CLI for individual plans. The motivation is simple and clear: lower the entry bar for users, give them a more pleasant experience from the start, and burn through subscription limits faster (thanks to an extra model call for every bash command).
But there’s another side to the coin. Because of this, many users don’t dig into the permission system at all and don’t think about isolating their local environment. Everything already looks safe: a smart model assesses every command it runs, so what could go wrong? A great deal, actually. Auto mode can’t protect against many attack vectors, and to work properly it needs some setup up front, in the form of a description of your working environment.
So is manual mode better and safer? Of course not, because the average user is far worse at analysing the risks of the commands being run and making a responsible decision. BUT in manual mode, to get rid of the inconvenience of constant manual reviews, users had a reason to figure out the permission system and the options for isolating environments. And to read in the documentation that auto mode doesn’t make using Claude Code safe at all.
For the curious, here’s a simple and elegant example of one possible attack vector that works perfectly well in auto mode.
Take care of yourselves and your agent environments!