Prompt injection researcher finds an attack that bypasses Claude Code's auto mode 80% of the time. The exploit tricks the agent into extracting a malicious zip that hijacks a local import, and auto mode can even block the agent's own cleanup commands. Rehberger urges sandboxing unattended coding agents to contain such threats.
Opening Kapyn…