Issue 005 — window: 24h to 06:00 UTC, 10 Aug 2026nofeed.dev
No. 005 · 10 August 2026 · 2 min← No. 004 · No. 006
SIGNALQUIET|SHIPPED 1|SKIPPED 5

The one thing

01

Claude Code makes auto mode the default on 14 Aug. The number that sold it: humans caught 13.6% of planted dangerous commands.

Starting 14 August, new Claude Code sessions on Pro, Max and Team open in auto mode unless you pinned something else.1 A classifier sits on every tool call and blocks irreversible, destructive or outward-bound actions; three blocks in a row, or twenty in a session, fall back to manual. Classifier overhead is free on those plans from today. Enterprise, the Claude API, Bedrock, Vertex and Foundry stay opt-in.

The study that carries it: 1,053 paid testers, one clearly dangerous command swapped into a real session. Humans refused 13.6% of the time. Auto mode blocked 89%.1 Human block rate fell from ~17% early to ~5% after fifty prompts; the classifier stayed flat. Confirmation fatigue, measured.

VERDICT · WAIT — already on auto mode — only the free classifier is new. On manual or YOLO, decide before the 14th: Shift+Tab still flips modes; admins can pin or disable auto. Do not read 89% as solved; eleven percent still gets through.
Deeper — what the number does not cover
  • Simon Willison walked the same post and is not there yet on prompt injection: zero of 720 Trajectory Labs attack attempts landed against Claude models in auto mode, but a malicious package whose install step looks like a normal test command is outside what a permission classifier can see.2
  • Auto mode is not --dangerously-skip-permissions. HN spent the morning mixing them up.3 The first still classifies; the second does not.
  • Hard denies (data exfiltration, external sends) stay hard. Admins can add more. For production infrastructure, Anthropic still says review the actions yourself.

Shipped

01
Use it

AI SDK · openai-compatible 3.0.28

Clamps outputTokens.text at zero when a provider reports more reasoning tokens than completion tokens — seen on Baseten when a reasoning model hits the length stop mid-thought.4

MATTERS TO · anyone metering usage behind an OpenAI-compatible proxy serving reasoning models
nofeed.dev/issues/2026-08-10/ai-sdk-openai-compatible-token-clamp/

Promised, not shipped
Claude Code auto mode default — 14 Aug 2026, Pro / Max / Team; Enterprise and cloud platforms later this month · Classifier overhead free on Enterprise and partner platforms — planned with the default flip, not yet

The conversation

01
The claim — including ours

The same study restates last week's permission game: humans are a leaking gate, and the leak gets worse the longer the session runs.1

From the floor
  • Simon Willison · simonwillison.netReads the study, keeps residual risk

    Buys that auto mode beats clicking OK all day. Does not buy that prompt injection is solved — wants confirmation beyond the vendor-commissioned Trajectory Labs eval, and names the malicious-package path a classifier cannot see.2

  • @bpodgursky · Hacker NewsThe useful correction

    Several commenters were arguing against YOLO. Auto mode still classifies; --dangerously-skip-permissions does not. Mixing them makes every safety claim sound like marketing.3

  • @quotemstr · Hacker NewsSandbox over prompt

    If the constraint is a prompt, you have already lost — point at real sandboxes rather than another model watching the first.3

Our take

The default is right for the median new user. The study is real evidence that human approval fails under load — same shape as the approval-game numbers in issue 004.

What changes here: when a vendor says safe because a human clicks yes, ask for the session-length curve. When they say a classifier is safe, ask what class of action it cannot see.

HN and a fresh Reddit pulse (six subreddits) ran today. X accounts (90) and X keyword digests last collected 05:30 UTC 9 Aug — over twelve hours old, background only. Vendor feeds: 12 polled, nothing in-window. GitHub releases: 28 repos, sweep complete.

Skip this

05

Everything we saw

42
42 candidates scanned · 8 used in this issue — the rest, with the reason each one was left out
The receipt. Ranking is only trustworthy if the discarded pile is visible, so here it is: everything the collectors surfaced in the window, with its signal and what we did with it.
ItemSourceSignalCall
Auto mode default in Claude Codeclaude.com106p · 66c HNled the issue
Simon Willison on auto modesimonwillison.netprimary readconversation
HN thread — Auto mode defaultnews.ycombinator.com66 commentsconversation
@ai-sdk/openai-compatible@3.0.28github releases12hshipped
Cline v4.1.7 / desktop 0.0.11 / cli 3.0.52github releases26h — just outside windowqueued for tomorrow if nothing larger lands
OpenChamberHN 132p72 commentswatching for a release we can pin
llama.cpp b10333github releases19hbackend patch
Gemini CLI nightliesgithub releasesprereleasepre-releases excluded
Reddit pulse — grill-me skill, DeepSeek V4 on CPU, embeddingsreddit pulse5 posts above floorfield colour, no primary
How I use LLMs to learn complex topicsHN 560p314 commentsessay, no toolchain change
Vendor status / changelogsvendor-feeds12 feeds, 0 in windowquiet
EOF

End of feed. That is everything from the window worth your time.
Next issue tomorrow, 06:00 UTC — and if nothing ships, it will say so in two hundred words.

Still developingAgent Plugins 1.0.0 (issue 004) — still one shipping client. Auto mode default lands 14 Aug; we re-check the residual 11% and any Enterprise schedule then.
Sources — each with the date it was read01 claude.com — auto mode default, 14 Aug (2026-08-10) · 02 simonwillison.net — auto mode notes (2026-08-10) · 03 news.ycombinator.com — auto mode thread (2026-08-10) · 04 github — @ai-sdk/openai-compatible@3.0.28 (2026-08-10)

Get it by email.

One issue every weekday. The whole thing, not a teaser.

Or RSS, if you would rather we never had your address.