Researcher Johann Rehberger bypassed Anthropic's Claude Code auto mode protections with an 80% success rate. The attack tricks the agent into executing a local Python file hidden within a zip archive. This vulnerability exposes a critical gap in the agent's ability to detect malicious local imports during automated coding tasks.