{"schema_version":"newruntime-agent-readable-v0.2","type":"post","stable_id":"post:claude-code-auto-mode-action-gate","slug":"claude-code-auto-mode-action-gate","title":"Claude Code Auto Mode Gates Actions Instead Of Explanations","description":"Claude Code Auto Mode combines an input injection probe with a two-stage action classifier, preserving autonomy while exposing an honest residual miss rate.","retrieval_nugget":"Claude Code Auto Mode combines an input injection probe with a two-stage action classifier, preserving autonomy while exposing an honest residual miss rate. Manual approval prompts degrade when nearly every prompt is accepted. Anthropic reports that users approved roughly 93% of Claude Code permission requests, creating a weak supervision loop.","status":"published","published_at":"2026-08-03","updated_at":"2026-08-03","record_date":"2026-08-03","date_kind":"published_at","topics":["agent-security","coding-agents","agent-harnesses","evals"],"source_urls":["https://www.anthropic.com/engineering/claude-code-auto-mode"],"visuals":[{"id":"claude-code-auto-mode-action-gate","kind":"editorial-diagram","role":"hero","src":"https://newruntime.com/images/posts/claude-code-auto-mode-action-gate.webp","alt":"Hand-drawn action pipeline where safe tools and project edits follow fast lanes, risky actions pass through a two-stage classifier, tool results pass through an injection probe, and repeated denials escalate to a person.","caption":"The classifier judges executable actions against user intent while a separate probe screens the content entering the agent loop.","credit":"New Runtime synthesis from Anthropic","source_url":"https://www.anthropic.com/engineering/claude-code-auto-mode","generated_with":"gemini-3.1-flash-image","width":1600,"height":900,"legend":[{"label":"Fast lanes","description":"Read-only tools and reviewable project edits avoid classifier latency."},{"label":"Action gate","description":"Shell, network, external tools, and out-of-project access are checked before execution."},{"label":"Input probe","description":"Suspicious tool output receives a warning before it enters the main agent context."},{"label":"Deny and continue","description":"A blocked action returns as a tool result so the agent can attempt a safer route."}]}],"routes":{"html":"https://newruntime.com/posts/claude-code-auto-mode-action-gate/","markdown":"https://newruntime.com/posts/claude-code-auto-mode-action-gate.md","json":"https://newruntime.com/posts/claude-code-auto-mode-action-gate.json"},"source_format":"markdown","next_reads":[{"type":"topic","path":"/topics/agent-security/","reason":"Explore the agent security topic hub.","url":"https://newruntime.com/topics/agent-security/","title":"Agent Security - New Runtime","media_type":"text/html"},{"type":"topic","path":"/topics/coding-agents/","reason":"Explore the coding agents topic hub.","url":"https://newruntime.com/topics/coding-agents/","title":"Coding agents - New Runtime","media_type":"text/html"},{"type":"related_material","path":"/posts/agentic-sdlc-software-factory-loop/","reason":"Shares agent harnesses and coding agents.","url":"https://newruntime.com/posts/agentic-sdlc-software-factory-loop/","title":"A Software Factory Connects Agents Through Verified Outcomes","media_type":"text/html"},{"type":"related_material","path":"/posts/cline-recursive-self-improvement-coding-agent/","reason":"Shares agent harnesses and coding agents.","url":"https://newruntime.com/posts/cline-recursive-self-improvement-coding-agent/","title":"Cline Turns Recursive Self-Improvement Into Harness Work","media_type":"text/html"},{"type":"related_material","path":"/posts/anthropic-agent-containment-blast-radius/","reason":"Shares agent harnesses and agent security.","url":"https://newruntime.com/posts/anthropic-agent-containment-blast-radius/","title":"Containment Caps An Agent's Blast Radius","media_type":"text/html"}]}
