Analysis · curated 9 Aug 2026

Auto mode is now the default in Claude Code for Pro, Max, and Team plans

Coverage timeline

8 Aug 2026simonwillison.netprimary

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Claude Code's auto mode defaulting on for millions of users shifts the trust model for coding agents, and Anthropic's bold claims to have 'mitigated every attack' including the lethal trifecta of prompt injection and exfiltration warrant scrutiny given the acknowledged 11% residual failure rate.

Anthropic is making Claude Code's 'auto mode' the default for Pro, Max, and Team plans starting August 14th, citing evaluations claiming strong resistance to prompt injection and data exfiltration. A commissioned third-party test by Trajectory Labs reported that none of 720 indirect prompt injection attempts succeeded against Claude models running auto mode across 72 scenarios, and a study of 1,053 developers found auto mode would block 89% of harmful actions versus 13.6% caught by human reviewers.