Voices
Willison on Auto Mode: 'Confirmation Fatigue Is Real' — But He Wants Independent Verification Before Believing Anthropic Solved Prompt Injection
Simon Willison endorsed the premise behind auto mode — 'asking humans to click OK every few steps is clearly not going to result in safe behavior' — while withholding judgment on the security claims, writing 'I would love to believe that Anthropic have indeed solved this problem for Claude Code users.' His specific unresolved worry is malicious third-party packages that appear credible to the model, a channel the injection evals don't cover. Willison has publicly predicted a coding-agent security disaster in 2026 and wants outside verification before accepting first-party numbers.
↳ Follow the thread