Evidence record / claude-code

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the signals and issues that cite it, below.

2026-09-21-claude-code-auto-mode-is-the-starting-mode-and-docs-list-isolation-needed-none

The permission-modes page describes auto mode as the built-in starting permission mode on Pro, Max and Team, and its table row for working hands-off in auto mode lists isolation needed as “None; a sandbox or container adds defense in depth”. The bypassPermissions section points users who want background safety checks to auto mode. On 2026-08-26 Johann Rehberger published an indirect prompt injection from a summarized web page that drove Claude Code on Opus 5 in auto mode to run attacker code, reporting 60 to 80 percent success, and wrote that Anthropic closed the report as Informative because auto mode is not a security boundary. The vendor’s response is reported by the researcher, not published by the vendor.

Channel: docs-only (permission-modes page observed 2026-09-23). Half: defect.

Operator consequence: Treat auto mode as a review layer, not isolation. Any session that reads untrusted web content in auto mode should also run in the Bash sandbox or a container with egress control; the docs call that defense in depth, the researcher’s result says it is the boundary.

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-claude-code-auto-mode-is-the-starting-mode-and-docs-list-isolation-needed-none

Profile citations

  • Claude Code / claim / auto-mode-starting-mode-isolation-none

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact