Auto mode's judge moved to the server; the docs still list its isolation as none
2.1.278 (2026-09-19, latest; stable is 2.1.267) makes the server-side classifier the auto-mode default for API, Enterprise, Bedrock, Vertex, Foundry and gateway sessions, four days after 2.1.273 set the local classifier as the cloud default. 2.1.271 lets the model name the egress hosts a sandboxed command needs, approved by the classifier with no human prompt. The permission-modes page lists auto mode as the starting mode on Pro, Max and Team with isolation needed "None". On 2026-08-26 a researcher published an auto-mode injection with 60 to 80 percent success and reported the vendor closed it as not a security boundary.
What this changes for operators
- Gateway operators: pass the safeguards request field and safeguard_results response field through, or set CLAUDE_CODE_AUTO_MODE_SERVER=0; otherwise the first checked action in each session holds. Record which classifier decided from /status.
- Run auto mode that reads untrusted content inside the Bash sandbox or a container with egress control. The docs call that defense in depth; the published attack says it is the boundary.
- Evidence that would settle residual: vendor documentation stating what the server-side classifier reviews and how its decisions are logged, and a vendor statement on whether auto mode is a security boundary.
Primary sources
- github_release 2026-09-21-claude-code-2-1-278-auto-mode-classifier-moves-server-side-by-default anthropics/claude-code / v2.1.278
- github_release 2026-09-21-claude-code-2-1-278-auto-mode-classifier-moves-server-side-by-default anthropics/claude-code / v2.1.273
- official_docs 2026-09-21-claude-code-2-1-278-auto-mode-classifier-moves-server-side-by-default code.claude.com/docs/en/auto-mode-classifier-billing
- official_docs 2026-09-21-claude-code-auto-mode-is-the-starting-mode-and-docs-list-isolation-needed-none code.claude.com/docs/en/permission-modes
- third_party_research 2026-09-21-claude-code-auto-mode-is-the-starting-mode-and-docs-list-isolation-needed-none embracethered.com/blog/posts/2026/breaking-claude-code-opus-5-and-automode/
- github_release 2026-09-21-claude-code-2-1-271-model-names-its-own-egress-hosts-subagent-output-framed-as-subagent anthropics/claude-code / v2.1.271
- github_release 2026-09-21-claude-code-2-1-271-model-names-its-own-egress-hosts-subagent-output-framed-as-subagent anthropics/claude-code / v2.1.277
- official_docs 2026-09-21-claude-code-2-1-271-model-names-its-own-egress-hosts-subagent-output-framed-as-subagent code.claude.com/docs/en/sandboxing#per-command-allowed-domains-in-auto-mode
Signal metadata
Source findings
- 2026-09-21-claude-code-2-1-278-auto-mode-classifier-moves-server-side-by-default 2026-09-21-claude-code-2-1-278-auto-mode-classifier-moves-server-side-by-default
- 2026-09-21-claude-code-auto-mode-is-the-starting-mode-and-docs-list-isolation-needed-none 2026-09-21-claude-code-auto-mode-is-the-starting-mode-and-docs-list-isolation-needed-none
- 2026-09-21-claude-code-2-1-271-model-names-its-own-egress-hosts-subagent-output-framed-as-subagent 2026-09-21-claude-code-2-1-271-model-names-its-own-egress-hosts-subagent-output-framed-as-subagent
Featured in
- Before the First Turn / 2026-09-21
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Schema: bitter.frontier_signals.v0 / ID: 2026-09-21-claude-code-auto-mode-judge-moved-server-side
Research evidence and publication history are open in the repository.