Auto mode for Claude Code
Summary
Anthropic introduced auto mode for Claude Code, a new permissions system where Claude automatically decides whether to allow actions with safeguards in place. A separate classifier model (Claude Sonnet 4.6) reviews each action before it runs to block requests that go beyond the task scope, target untrusted infrastructure, or appear malicious, using customizable default filters that cover allowed operations like read-only requests and local file work, while blocking risky actions like force-pushing to git repositories or executing external code.
Classification
Affected Vendors
Related Issues
Original source: https://simonwillison.net/2026/Mar/24/auto-mode-for-claude-code/#atom-everything
First tracked: March 25, 2026 at 02:00 AM
Classified by LLM (prompt v3) · confidence: 85%