Analysis · curated 9 Aug 2026

Auto mode is now the default in Claude Code for Pro, Max, and Team plans

Coverage timeline

8 Aug 2026simonwillison.netprimary

Why it matters

Prompt injection and data exfiltration remain the central security threats to autonomous coding agents, and Anthropic's claim to have largely mitigated these attacks in Claude Code's default mode is a significant, if unverified, development for defenders assessing agentic-AI risk.

Anthropic is making 'auto mode' the default in Claude Code for Pro, Max, and Team plans starting August 14th, and published evals claiming strong resistance to prompt injection and accidental harmful actions. A third-party evaluation by Trajectory Labs reportedly found none of 720 indirect prompt-injection attack attempts succeeded against Claude models in auto mode, and a controlled study of 1,053 developers found auto mode would have blocked 89% of harmful actions versus 13.6% for human reviewers. Simon Willison analyzes the claims skeptically, noting 11% of harmful cases would still slip through.