Researcher Johann Rehberger bypassed Anthropic's Claude Code auto mode with an attack that succeeds 80% of the time. The exploit tricks the agent into executing a local Python file hidden within a zip archive. This failure exposes critical gaps in the agent's prompt injection defenses. Practitioners should avoid trusting autonomous coding agents with sensitive environments.