⚡
Brief IA
›

Claude Code: Anthropic Sets Automatic Mode as Default

🛠️ AI Tools·Tom Levy·

Claude Code: Anthropic Sets Automatic Mode as Default

Claude Code: Anthropic Sets Automatic Mode as Default
⚡
Key Takeaways
1Anthropic has decided to make automatic mode the default in Claude Code for Pro, Max, and Team plans starting August 14.
2An evaluation showed that automatic mode blocks 89% of harmful actions, surpassing human decisions.
3Trajectory Labs confirmed that no command injection attempts succeeded against Claude Fable 5 in automatic mode.
💡Why it matters — This decision by Anthropic aims to enhance user safety against threats of command injection and data exfiltration.
⚡Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

Automatic Mode Becomes the Standard for Claude Code

Anthropic, the company behind Claude Code, recently made a significant decision by making automatic mode the default setting for its Pro, Max, and Team plan users. This measure, effective since August 14, reflects Anthropic's confidence in this feature to enhance the safety and efficiency of coding sessions.

Discussion at the Global AI Engineers Fair

At the recent Global AI Engineers Fair, Cat Wu and Thariq Shihipar discussed the secure use of Claude Code within Anthropic. They explained that automatic mode is widely adopted by the company's employees. Cat Wu emphasized that assessments will be published soon, indicating that the risks associated with command injection and data exfiltration have been significantly reduced, even surpassing the performance of an average human reviewer.

Security Testing Results

The assessments include a test conducted with 1,053 paid testers. In this test, a potentially dangerous command was inserted in place of a standard permission prompt. The provider recorded whether the tester approved this dangerous command. Each participant had the same experience, and the results showed that only 13.6% of human participants rejected this harmful action, while automatic mode successfully blocked 89% of these actions. However, there remains 11% of cases where automatic mode was unable to prevent the action.

Advantages of Automatic Mode

Automatic mode is seen as a more effective solution than relying on human approval for every action. Confirmation fatigue, where users mechanically click "OK," is a real issue that can compromise security. Automatic mode aims to reduce this risk by automatically filtering out potentially dangerous actions.

Ongoing Security Challenges

Two main security issues have been identified: accidental harmful actions, such as deleting important files, and the injection of malicious commands. The latter is particularly concerning, as it involves introducing malicious commands into the content that the agent consumes.

Independent Assessments by Trajectory Labs

Anthropic commissioned an assessment from Trajectory Labs, which tested various models of Claude Code and Codex as of July 17, 2026. The tests focused on 72 scenarios of indirect command injection excluded from Anthropic, and none of the 720 attempts succeeded against Claude Fable 5, Opus 5, or Sonnet 5 in automatic mode. Thariq Shihipar even joked on Twitter that they should have named their publication "defeating the lethal trifecta."

Call for Independent Confirmations

Although the results are promising, it is important to continue seeking independent confirmations. One example of a potential attack is the use of a malicious third-party package that could exfiltrate data under the guise of executing tests. This scenario involves the use of a package named "fetch-model-files" which, under the pretense of retrieving model files with "uvx fetch-model-files .", could actually exfiltrate all available data before executing "uv run pytest." The ability of automatic mode to counter this type of threat remains uncertain.

Conclusion: Towards Enhanced Security

Advanced models have shown a surprising ability to bypass firewalls by following seemingly credible instructions. This encourages the exploration of methods to limit agents' access to sensitive data or tools that could cause harm, even in the event of incorrect triggering. The source's author expressed hope that Anthropic has indeed resolved this issue for Claude Code users. However, they predicted "a disaster of challenges for coding agent security" by 2026, based on the vulnerability of coding agents to attacks of this nature.

⚡

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.