Anthropic / News

Claude Code --dangerously-skip-permissions: what it does, tested

We gave Claude Code one coding job in four permission modes. Skip permissions was fastest (16 seconds) with every secret check passed, but auto mode passed them all too, with a safety check on each step.

Table of our test: one coding job in four Claude Code permission modes. Manual 0 of 45 secret checks, acceptEdits 45 of 45 but tests blocked, Auto 45 of 45 in 24 seconds, skip permissions 45 of 45 in 16 seconds
Our own test in a throwaway Linux sandbox, 10 October 2026. Chart by Not an AI App.

Claude Code normally asks before it changes files or runs commands. The flag --dangerously-skip-permissions turns those questions off. We tested what that really changes. We gave Claude Code the same small coding job in four permission modes, with nobody there to click "yes". Skipping permissions was the fastest: 16 seconds per job and every secret check passed. But auto mode also passed every check, in 24 seconds, with a safety check on each action.

What does --dangerously-skip-permissions do?

Screenshot of Anthropic's table of permission modes: default reads only; acceptEdits reads, file edits and common filesystem commands; plan; auto everything with background safety checks; dontAsk; bypassPermissions everything, for isolated containers and VMs only
Anthropic's Claude Code docs, page Choose a permission mode. Screenshot from 10 October 2026, cropped.

Claude Code has several permission modes. A permission mode decides what Claude may do without asking you first. The flag --dangerously-skip-permissions starts Claude Code in the mode called bypassPermissions. Anthropic's docs put it simply: "The --dangerously-skip-permissions flag is equivalent."

In that mode, Claude may do "Everything" without asking: change files, run any command and use the internet. The docs describe it as the mode for "Isolated containers and VMs only". A container or VM (virtual machine) is a separate, closed-off computer inside a computer, so nothing important can break.

A few things still need your approval even then. One example is deleting very important folders, like your whole home folder.

Our test: one job, four modes

Diagram of our test: one coding job, four permission modes (Manual, acceptEdits, Auto, skip permissions), the same 15 secret checks, blocked actions and time
Diagram by Not an AI App.

We wrote one small coding job: build a function called slugify. It turns a title like "Crème brûlée, 2 ways" into a web address part like "creme-brulee-2-ways". The job came with a short spec of eight rules. Afterwards we checked the work with 15 secret checks that Claude never saw.

We ran Claude Code with Sonnet 5.5 in four modes, three tries each:

  • Manual: the classic mode that asks before almost everything.
  • acceptEdits: Claude may change files, but must still ask to run commands.
  • Auto: a second AI model checks each action and blocks risky ones.
  • Skip permissions: --dangerously-skip-permissions, no questions at all.

We ran Claude Code with claude -p, which means it works on its own. Nobody was there to answer a question. That is how people run Claude Code in scripts, or when they leave it alone for a long task.

What happened in each mode

Bar chart of the time per job: Manual 26 seconds, acceptEdits 24 seconds, Auto 24 seconds, skip permissions 16 seconds, with the number of steps
Our own test, 10 October 2026, middle of three tries per mode. Chart by Not an AI App.
  • Manual: 0 of 45 secret checks. Claude wanted to write the code and run the tests, but every one of those steps was blocked: 4 blocked actions per try. Nothing changed.
  • acceptEdits: 45 of 45. Claude could write the files, so the code was there and it was correct. But it was not allowed to run node --test, so it could not check its own work.
  • Auto: 45 of 45, no blocked actions, about 24 seconds. The safety check let every step through, including running the tests.
  • Skip permissions: 45 of 45, no blocked actions, about 16 seconds.

So skip permissions was about a third faster than auto mode on this job. It also needed fewer steps: 5 instead of 6. The quality was the same.

acceptEdits: done, but not checked

Claude Code's last message in acceptEdits mode: I couldn't run node --test, the command was blocked, I haven't verified either. And in Manual mode: nothing in the project has changed.
Claude Code's own final answers in our test of 10 October 2026, typed out as an image by Not an AI App.

The most interesting result was acceptEdits. The code it wrote passed all our secret checks. But Claude did not know that, because it was not allowed to run the tests. To its credit, it said so plainly in its last message: "I wrote the implementation and tests, but I haven't verified either."

In Manual mode it was just as honest: "Nothing in the project has changed." So when Claude Code works on its own, check which mode it ran in. A job that looks done may not have been tested.

Is auto mode the same as skip permissions?

Screenshot of Anthropic's docs: Auto mode lets Claude execute without routine permission prompts. A separate classifier model reviews actions before they run.
Anthropic's Claude Code docs. Screenshot from 10 October 2026, cropped.

No. This is the question many people ask, and the difference matters. In auto mode, "a separate classifier model reviews actions before they run", Anthropic's docs say. A classifier is a second AI model that judges each step. It blocks anything "that escalates beyond your request, targets unrecognized infrastructure, or appears driven by hostile content Claude read".

With skip permissions, there is no such check. In our test that made no difference to the result: both modes passed every secret check. It only made skip permissions faster. But our job was small and harmless. The check in auto mode is there for the moments when something goes wrong.

Since Claude Code version 2.1.283, auto mode is where interactive sessions in the terminal and VS Code start, the docs say.

Why is it called dangerous?

Screenshot of a warning in Anthropic's docs: bypassPermissions offers no protection against prompt injection or unintended actions; use auto mode instead; administrators can block this mode
Anthropic's Claude Code docs. Screenshot from 10 October 2026, cropped.

Because Claude can then do anything your computer account can do, without stopping. If it misunderstands a job, it can change or delete the wrong files. If it reads a web page or a file with hidden instructions in it, nothing stops it from following them. That trick is called prompt injection.

Anthropic is clear about this in its docs: skip permissions "offers no protection against prompt injection or unintended actions". The same warning advises auto mode "for background safety checks with far fewer permission prompts".

Anthropic built in some brakes. On Linux and macOS, Claude Code refuses this mode when you run it as root, the all-powerful admin account, unless it is inside a sandbox it recognizes. Deleting very important folders still asks first. And companies can switch the mode off for everyone.

How to turn it on, and off

Overview of commands: claude --dangerously-skip-permissions, claude --permission-mode bypassPermissions, claude --permission-mode auto, claude --permission-mode acceptEdits, and the setting disableBypassPermissionsMode
Commands from Anthropic's Claude Code docs, read on 10 October 2026. Image by Not an AI App.

To start Claude Code without permission questions, use one of these, from Anthropic's docs:

  • claude --dangerously-skip-permissions
  • claude --permission-mode bypassPermissions (the same thing, written out)

For fewer questions with a safety check, use claude --permission-mode auto. To only allow file edits, use claude --permission-mode acceptEdits.

To block skip permissions, even for yourself, put "disableBypassPermissionsMode": "disable" under "permissions" in a Claude Code settings file. You can also allow single commands with permission rules, so Claude stops asking about the things you trust. We used hooks for something similar in our Claude Code mods test.

Where can you use it safely?

Diagram: we ran the test in a throwaway Linux sandbox at Vercel as a normal user, not on our own PC, following Anthropic's advice to use this mode only in isolated containers or VMs
Diagram by Not an AI App.

Anthropic's advice is to use skip permissions only in a closed-off place, such as a container or a VM. It offers a ready-made dev container for this, which runs Claude Code as a normal user instead of root.

That is what we did. We ran all twelve tries in a fresh Linux sandbox at Vercel, as a normal user, with no personal files, passwords or keys in it. After the test, the sandbox was deleted. We did not run skip permissions on our own PC.

If you just want fewer questions on your own computer, auto mode is the better choice. In our test it did the job just as well, only a bit slower.

Questions people ask

List of questions people ask Google about Claude Code's skip permissions flag, with the 6 questions we answer marked
"People also ask" questions from Google (US), 10 October 2026, via DataForSEO. Chart by Not an AI App.

What does dangerously skip permissions do?

It turns off Claude Code's permission prompts. Claude can then edit files, run commands and reach the internet without asking you first. Anthropic's docs say the flag is the same as the mode bypassPermissions. In our test it made a small coding job about a third faster than the other modes.

Is auto mode the same as dangerously skip permissions?

No. In auto mode, a second AI model checks each action before it runs and can block it. With skip permissions, nothing is checked. In our test both finished the job with every secret check passed. Auto took about 24 seconds, skip permissions about 16.

How do I get Claude Code to stop asking for permissions?

Start it in auto mode with claude --permission-mode auto. A safety check then replaces most prompts. You can also allow specific tools or commands with permission rules. Only use --dangerously-skip-permissions in a sandbox, container or virtual machine, as Anthropic advises.

Why is Claude Code always asking for permission?

Because it is in Manual mode, which asks before most edits, commands and web requests. In our test, Manual mode with nobody there to say yes changed nothing at all. Since version 2.1.283, Claude Code starts in auto mode in the terminal and VS Code, which asks much less.

Can Claude Code access all your files?

Normally it can read files in your project folder without asking, and it asks before other actions. With --dangerously-skip-permissions it asks almost nothing, so it can do whatever your user account can do. That is why Anthropic says to use that mode only in isolated containers or virtual machines.

How to launch Claude Code in yolo mode?

"Yolo mode" is a nickname for claude --dangerously-skip-permissions. The long form is claude --permission-mode bypassPermissions. On Linux and macOS it refuses to start as root, unless it runs in a sandbox Claude Code recognizes. We ran it in a throwaway Linux sandbox, not on our own PC.

How we checked

Table of blocked actions per try: Manual 3 file writes and 1 test run, acceptEdits 1 shell write and 2 test runs, Auto and skip permissions none
From Claude Code's own report of blocked actions in our test, 10 October 2026. Chart by Not an AI App.

On 10 October 2026 we read Anthropic's Claude Code docs on permission modes and permissions. The screenshots are our own captures of those pages, cropped only.

We ran the test the same day in a Vercel Sandbox with Linux, Claude Code 2.1.296 and Claude Sonnet 5.5 at effort "medium": 1 job, 4 modes, 3 tries, so 12 runs. Claude Code logged in with the site owner's Claude subscription. The secret checks never went into the sandbox: we copied the finished code back and checked it on our own PC. Times are from start to finish of each run. The blocked actions come from Claude Code's own report.

This was one small, harmless job. It shows how the modes behave, not how safe each one is when something goes wrong. More about what Claude Code costs is in our pricing test, and how it compares with Cursor in Cursor vs Claude Code. The charts were made by us. None of the images was made by AI.