Summary
In auto mode, the permission classifier repeatedly blocks actions that the user has explicitly and directly ordered in the same session, which stalls long-running work. The denial reasons are either absent ("judged this action dangerous (it gave no explanation)") or generic, and the agent is then instructed to stop and hand the action back to the user, even though the user already gave the instruction.
Observed denials (single session, one multi-agent setup)
- "Merge Without Review" – The user explicitly ordered the agent to merge a pull request it had just opened ("merge it yourself"). Both
git push <sha>:main (fast-forward) and gh pr merge --merge were denied. The user then had to merge manually.
- No explanation given – A small local shell script that only ran
git commit-tree, pushed a branch, opened a PR and updated the local branch ref was denied with "judged this action dangerous (it gave no explanation)". Running the same steps individually later worked except the merge.
- No explanation given – A deployment step the user had explicitly ordered ("deploy it") was denied when written to a helper script; the same command run directly later succeeded.
- Credential exploration – A parallel session was asked to read test-account credentials that the user had placed in a user environment variable specifically for load testing. The read was denied as credential exploration.
- "Production Reads" – A parallel session, doing post-deployment verification the user had ordered, was denied reading the results of its own verification run on the deployed test environment.
Impact
- Work that the user ordered stops mid-way, and the agent is told to ask the user to run the command themselves. The user experiences this as the agent refusing their instruction.
- The same denial repeats in later turns because the agent cannot record that the user already authorized it.
- Denials without an explanation give neither the agent nor the user anything to act on.
Requests
- Take an explicit, in-session user instruction for the exact action into account (e.g. "merge this PR", "deploy", "use the test accounts in env var X").
- Always include a concrete reason in the denial.
- Provide a documented way for the user to authorize a recurring class of action for the session, without editing settings files mid-task.
Environment
- Claude Code (VS Code extension), Windows 11, auto mode
- Multiple Claude Code sessions running in parallel on one machine
Summary
In auto mode, the permission classifier repeatedly blocks actions that the user has explicitly and directly ordered in the same session, which stalls long-running work. The denial reasons are either absent ("judged this action dangerous (it gave no explanation)") or generic, and the agent is then instructed to stop and hand the action back to the user, even though the user already gave the instruction.
Observed denials (single session, one multi-agent setup)
git push <sha>:main(fast-forward) andgh pr merge --mergewere denied. The user then had to merge manually.git commit-tree, pushed a branch, opened a PR and updated the local branch ref was denied with "judged this action dangerous (it gave no explanation)". Running the same steps individually later worked except the merge.Impact
Requests
Environment