Researcher chains prompt injection into code execution in Claude Code's Auto Mode
Anthropic closed the report as 'informative' rather than a vulnerability requiring a fix, saying the classifier is a best-effort convenience feature, not a security guarantee.
AnthropicSecurity & misuse