Researcher Johann Rehberger bypassed Anthropic's Claude Code auto mode security with an 80% success rate. The attack tricks the agent into executing a local Python file hidden within a zip archive. This vulnerability undermines claims that auto mode protects users from prompt injection. Developers should treat agentic code execution as inherently untrusted.