Compare AIFind AIAI NewsAI How-To
About Us
PrivacyTermsFAQContactContact
AIB Inc.Company info
© 2026 AIB Inc.

Claude Code Auto Mode Bypassed

Claude Code Auto Mode Bypassed

Simon Willison·Friday, August 28, 2026
  • •Johann Rehberger found a Claude Code auto mode attack he said worked 80% of the time
  • •Claude Code was tricked into unzipping an archive and executing a local struct.py file
  • •Simon Willison said unattended coding agents need sandboxes, restricted network egress and credential isolation
  • •Johann Rehberger found a Claude Code auto mode attack he said worked 80% of the time
  • •Claude Code was tricked into unzipping an archive and executing a local struct.py file
  • •Simon Willison said unattended coding agents need sandboxes, restricted network egress and credential isolation
  • •Johann Rehberger found a Claude Code auto mode attack he said worked 80% of the time
  • •Claude Code was tricked into unzipping an archive and executing a local struct.py file
  • •Simon Willison said unattended coding agents need sandboxes, restricted network egress and credential isolation
  • •Johann Rehberger found a Claude Code auto mode attack he said worked 80% of the time
  • •Claude Code was tricked into unzipping an archive and executing a local struct.py file
  • •Simon Willison said unattended coding agents need sandboxes, restricted network egress and credential isolation

Simon Willison reported on August 27, 2026 that Anthropic’s Claude Code auto mode, recently made the default protection for coding-agent users, was bypassed by a prompt injection attack found by Johann Rehberger. Anthropic had described auto mode as an effective defense, but Rehberger said his attack worked 80% of the time against that safety mechanism.

The attack tricked Claude Code into downloading and uncompressing a zip archive, then running code that imported base64. According to the account, that import caused Python to load and execute a local struct.py file extracted from the archive, rather than simply using the expected standard-library path. The test targeted prompt injection (malicious instructions hidden in input) against an unattended coding agent.

Willison said auto mode sometimes made the incident worse after compromise. In several runs, Claude noticed the malware process and tried to terminate it, but Auto Mode denied the cleanup command. The same classifier that allowed creation of the malware process then blocked the command intended to stop it.

Willison agreed with Rehberger’s conclusion that unattended coding agents facing adversarial input should run in a sandbox (isolated runtime environment). The recommended controls were to run agents in a container, VM or OS sandbox, restrict network egress, monitor agent activity, and avoid exposing home directories, SSH keys, cloud credentials or similar secrets to the agent runtime.

Simon Willison reported on August 27, 2026 that Anthropic’s Claude Code auto mode, recently made the default protection for coding-agent users, was bypassed by a prompt injection attack found by Johann Rehberger. Anthropic had described auto mode as an effective defense, but Rehberger said his attack worked 80% of the time against that safety mechanism.

The attack tricked Claude Code into downloading and uncompressing a zip archive, then running code that imported base64. According to the account, that import caused Python to load and execute a local struct.py file extracted from the archive, rather than simply using the expected standard-library path. The test targeted prompt injection (malicious instructions hidden in input) against an unattended coding agent.

Willison said auto mode sometimes made the incident worse after compromise. In several runs, Claude noticed the malware process and tried to terminate it, but Auto Mode denied the cleanup command. The same classifier that allowed creation of the malware process then blocked the command intended to stop it.

Willison agreed with Rehberger’s conclusion that unattended coding agents facing adversarial input should run in a sandbox (isolated runtime environment). The recommended controls were to run agents in a container, VM or OS sandbox, restrict network egress, monitor agent activity, and avoid exposing home directories, SSH keys, cloud credentials or similar secrets to the agent runtime.

Read original (English)·Aug 27, 2026
Coding#claude code#auto mode#prompt injection#sandboxing#johann rehberger#simon willison#coding agent#network egress#struct py