Signals

2026-09-21 / Claude Code

Auto mode's judge moved to the server; the docs still list its isolation as none

Edited by Michael Ruescher

2.1.278 (2026-09-19, latest; stable is 2.1.267) makes the server-side classifier the auto-mode default for API, Enterprise, Bedrock, Vertex, Foundry and gateway sessions, four days after 2.1.273 set the local classifier as the cloud default. 2.1.271 lets the model name the egress hosts a sandboxed command needs, approved by the classifier with no human prompt. The permission-modes page lists auto mode as the starting mode on Pro, Max and Team with isolation needed "None". On 2026-08-26 a researcher published an auto-mode injection with 60 to 80 percent success and reported the vendor closed it as not a security boundary.

What this changes for operators

  • Gateway operators: pass the safeguards request field and safeguard_results response field through, or set CLAUDE_CODE_AUTO_MODE_SERVER=0; otherwise the first checked action in each session holds. Record which classifier decided from /status.
  • Run auto mode that reads untrusted content inside the Bash sandbox or a container with egress control. The docs call that defense in depth; the published attack says it is the boundary.
  • Evidence that would settle residual: vendor documentation stating what the server-side classifier reviews and how its decisions are logged, and a vendor statement on whether auto mode is a security boundary.

Signal metadata

Source findings

Featured in

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Schema: bitter.frontier_signals.v0 / ID: 2026-09-21-claude-code-auto-mode-judge-moved-server-side

Research evidence and publication history are open in the repository.