Researcher Johann Rehberger bypassed Anthropic's Claude Code auto mode protections with an 80% success rate. The attack tricks the agent into downloading a zip archive and executing a local Python file via a base64 import. This failure exposes critical vulnerabilities in automated coding agents. Practitioners must maintain manual oversight of agent-led file executions.