Skip to content

Auto mode classifier blocks actions the user explicitly ordered in-session (merge, deploy, reading test credentials, verification reads) #98478

Description

Summary

In auto mode, the permission classifier repeatedly blocks actions that the user has explicitly and directly ordered in the same session, which stalls long-running work. The denial reasons are either absent ("judged this action dangerous (it gave no explanation)") or generic, and the agent is then instructed to stop and hand the action back to the user, even though the user already gave the instruction.

Observed denials (single session, one multi-agent setup)

  1. "Merge Without Review" – The user explicitly ordered the agent to merge a pull request it had just opened ("merge it yourself"). Both git push <sha>:main (fast-forward) and gh pr merge --merge were denied. The user then had to merge manually.
  2. No explanation given – A small local shell script that only ran git commit-tree, pushed a branch, opened a PR and updated the local branch ref was denied with "judged this action dangerous (it gave no explanation)". Running the same steps individually later worked except the merge.
  3. No explanation given – A deployment step the user had explicitly ordered ("deploy it") was denied when written to a helper script; the same command run directly later succeeded.
  4. Credential exploration – A parallel session was asked to read test-account credentials that the user had placed in a user environment variable specifically for load testing. The read was denied as credential exploration.
  5. "Production Reads" – A parallel session, doing post-deployment verification the user had ordered, was denied reading the results of its own verification run on the deployed test environment.

Impact

  • Work that the user ordered stops mid-way, and the agent is told to ask the user to run the command themselves. The user experiences this as the agent refusing their instruction.
  • The same denial repeats in later turns because the agent cannot record that the user already authorized it.
  • Denials without an explanation give neither the agent nor the user anything to act on.

Requests

  • Take an explicit, in-session user instruction for the exact action into account (e.g. "merge this PR", "deploy", "use the test accounts in env var X").
  • Always include a concrete reason in the denial.
  • Provide a documented way for the user to authorize a recurring class of action for the session, without editing settings files mid-task.

Environment

  • Claude Code (VS Code extension), Windows 11, auto mode
  • Multiple Claude Code sessions running in parallel on one machine

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions