Claude Code auto mode: a safer way to skip permissions
… Why the prompt-injection probe matters The transcript classifier's injection defense is structural as it never sees tool results. But the main agent does see tool results, and an injection that hijacks the main agent then has a chance of bypassing the transcript monitor too. …