tuesday, october 6, 2026 · the day's ai, attributed published by trilot llc · wyoming
archive · today in ai · 2026-08-29

Researcher breaks Claude Code's Auto Mode

Archive item — written before sources were shown.

A prompt-injection researcher got Claude Code's Auto Mode to run remote code by asking it to summarize a booby-trapped website, 60 to 80 percent of the time.

Security researcher Johann Rehberger published a working attack against Claude Code Opus 5’s Auto Mode, the setting that lets Claude Code act without asking for confirmation on each step. The attack starts with an innocuous request: summarize a website. That website contains a booby-trapped zip archive. When Claude downloads and unpacks it to summarize the contents, it later imports Python’s standard base64 module from inside that same extracted directory. Because Python searches the current directory first when resolving imports, and the archive included a file named struct.py, Claude’s own decoder ends up loading the attacker’s file instead of the real standard-library module, since base64 itself imports struct internally.

The planted struct.py then launches a separate Python process that downloads and runs a second-stage payload, in Rehberger’s proof of concept, opening the Calculator app as a visible signal of compromise, though a real attacker could do anything with the same access. Rehberger reports the attack succeeds 60 to 80 percent of the time across his tests, and used ChatGPT to obfuscate the malicious code enough to slip past Claude’s own safety review of what it was about to run.

Why this one matters more than most

Auto Mode is specifically the setting people enable to reduce friction, trading step-by-step confirmation for speed. This attack shows that trade costs more than expected: a single “summarize this page” request, the kind of task Auto Mode exists to handle without interruption, was enough to trigger code execution through a language-level quirk rather than an obvious jailbreak. It is closely related to the llms.txt supply-chain research published the same week, where coding agents ran unvetted install commands found in ordinary-looking documentation, and it echoes the same lesson as Cursor’s own git.exe auto-execution flaw: anything an agent reads while running with elevated permissions is a potential instruction, and the industry has not yet closed that gap.

sources
  1. 01Breaking Claude Code Opus 5 Auto Mode with Indirect Prompt Injectionembracethered.com · primary research
  2. 02Breaking Claude Code Opus 5 Auto Modesimonwillison.net · independent analysis
Rami Steitieh
Rami Steitieh

Builder and operator. Runs 17 content sites and Trilot LLC on the tools reviewed here.