Researcher Johann Rehberger bypassed Anthropic's Claude Code auto mode safety filters with an 80% success rate. The attack tricks the agent into executing a local Python file hidden within a zip archive. This vulnerability exposes a critical flaw in the agent's ability to detect malicious local imports during autonomous coding tasks.