Claude Code auto mode: a safer way to skip permissions
… Because the input is identical other than the final instruction, stage 2's prompt is almost entirely cache-hit from stage 1. Why the prompt-injection probe matters The transcript classifier's injection defense is structural as it never sees tool results. …