Hivra
With the prompts off, the thing around Claude Code is your protection.

Claude Code's --dangerously-skip-permissions flag: what it skips and where to run it

One flag turns off Claude Code's permission prompts, and Anthropic says to use it only inside a container or VM. We went through Anthropic's and OpenAI's docs and checked Hivra's defaults against our own code. Short version: a few checks survive the flag. A separate computer keeps a mistake off your laptop. Anything you sign in to on it is still fair game.

Short answer

Claude Code's --dangerously-skip-permissions flag turns off its permission prompts, so commands and edits run without asking. Anthropic says to run it only in a container or VM as a non-root user. Auto mode is the safer hands-off pick. A separate computer protects your laptop. It doesn't protect what you sign in to on it.

What does --dangerously-skip-permissions do?

It starts Claude Code in bypassPermissions mode, which turns the permission prompts off. Tool calls run at once, and that includes writes to protected paths such as .git and .claude. The flag and --permission-mode bypassPermissions do the same thing (CLI reference, permission modes).

The Anthropic facts here come from its own docs. Some depend on your Claude Code version, so run claude --version before you trust a line.

Not everything switches off. Deny rules still block in every mode, bypass included, and ask rules still prompt. Allow rules do nothing here: with the flag on, an allowlist that leaves out rm doesn't stop rm.

Then there are the protected paths. With the flag on, Claude Code writes to .git, .claude, .vscode, .idea, .husky and a few more folders without asking. It does the same for files such as .gitconfig, .bashrc, .zshrc, .npmrc and .mcp.json. Manual and accept-edits modes prompt for those writes. Anthropic guards them in those other modes to protect your repository state and Claude's own configuration.

Is --dangerously-skip-permissions safe?

Not by itself. Anthropic's docs say bypass mode offers no protection against prompt injection or unintended actions, so whatever surrounds Claude Code is the protection you have. Anthropic says to use the mode only in isolated environments such as containers, VMs or dev containers, and its warning adds "without internet access". On its sandbox page it says to always run the flag inside a container, a VM or the sandbox runtime, so file tools, MCP servers and hooks sit inside the boundary too.

It goes wrong in ordinary ways. The model points a delete at the wrong path, or reads a file or web page whose text steers it somewhere you never wanted it to go. Or it ends up holding a login, a key or a tool server you didn't mean to hand over. We don't know how often any of that happens, and we won't guess.

Isolation helps, with a limit Anthropic states itself. It cuts the impact of a breach and doesn't remove the risk: an agent with network access can still leak what it can read, and a writable project mount can still be changed.

People reach for the flag because prompts wear them out. Anthropic's engineering post on auto mode, dated 25 March 2026, says users approve 93% of permission prompts. A prompt you click through that often was never much of a guard.

What are Claude Code's permission modes?

Six: Manual, acceptEdits, plan, auto, dontAsk and bypassPermissions. This table is from Anthropic's permission modes page. Manual is the label for the config value default.

ModeRuns without askingStart it with
default (Manual)Reads only--permission-mode default
acceptEditsReads, file edits and common filesystem commands such as mkdir, touch, rm, mv and cp, inside the working directory--permission-mode acceptEdits
planReads, plus classifier-approved commands when auto mode is available. Edits wait for a plan you approve--permission-mode plan
autoEverything, with background safety checks by a second model--permission-mode auto
dontAskReads and pre-approved tools. Anything that would prompt is denied--permission-mode dontAsk
bypassPermissionsEverything--dangerously-skip-permissions

The Manual label and the manual alias need v2.1.200 or later. Auto mode has been the built-in starting mode for terminal and VS Code sessions since v2.1.283, and before that only on Pro, Max and Team plans. On the Anthropic API, auto needs Opus 4.6 or later, Sonnet 4.6 or later or a Fable model, and admins can turn it off. dontAsk never shows up in the Shift+Tab cycle, so you set it with the flag.

Each app handles bypass its own way. VS Code needs its Allow dangerously skip permissions toggle. The desktop app needs Allow bypass permissions mode on Pro and Max, and organization policy decides on Team and Enterprise. Anthropic's cloud sessions don't offer bypass at all.

Should I use Claude Code's auto mode instead of --dangerously-skip-permissions?

On your own laptop, yes. Auto mode puts a second model, a classifier, in front of risky actions, which is a check the flag doesn't have. It blocks actions that go beyond what you asked, aim at infrastructure it doesn't recognise, or look driven by hostile content Claude read. After 3 blocks in a row or 20 in total it pauses and prompts you again. Anthropic's docs still warn that auto mode reduces prompts without guaranteeing safety.

Anthropic published error rates for the classifier in the engineering post dated 25 March 2026. On 10,000 real tool calls from Anthropic's own staff, it wrongly blocked 0.4% of them. It let through 17% of 52 real cases where the agent went past what the user had authorised, and 5.7% of 1,000 synthetic data-exfiltration attempts. That 52 is a small set, and Anthropic calls the 17% the honest number. The same post calls auto mode a substantial improvement for people running the flag, then adds that it won't replace careful review on high-stakes infrastructure. Sonnet 5 is the default classifier model in the docs now, and we found no newer figures, so read those rates as March's, not today's.

Anthropic calls the classifier a per-action control and says a container still adds a layer for unattended runs. For the flag, its docs say to use a container or VM. Auto mode doesn't come with that rule.

On a Hivra computer, Chat passes the skip flag by default. It doesn't pass auto mode.

What is the Codex equivalent of --dangerously-skip-permissions?

It's --dangerously-bypass-approvals-and-sandbox, which OpenAI also lets you type as --yolo. It turns off approvals and the sandbox together. OpenAI's CLI reference says to use it only inside an externally hardened environment, and its approvals page lists it as no sandbox, no approvals, not recommended.

Codex splits the dial in two:

SettingValues
--sandboxread-only, workspace-write, danger-full-access
--ask-for-approvalon-request, never

-a never works with every sandbox mode, so you can switch the prompts off and keep the sandbox. OpenAI's advice for unattended local work that can stay inside the workspace is --sandbox workspace-write, and to avoid the bypass flag unless you're inside a dedicated sandbox VM.

On launch, Codex checks whether the folder is version controlled. For one that is, OpenAI recommends the Auto preset, which is workspace-write with on-request approvals. For any other folder it recommends read-only. OpenAI documents the workspace-write sandbox as keeping network access off until you turn it on in config (sandbox_workspace_write.network_access). That's OpenAI's stated default for the CLI. We haven't checked it on a Hivra computer.

OpenAI gives the same warning Anthropic does. With the bypass flag or danger-full-access inside a devcontainer, a malicious project can exfiltrate anything available there, Codex credentials included, so use that pattern only with trusted repositories.

Where should I run --dangerously-skip-permissions so a mistake can't touch my laptop?

Inside a container, a VM or Anthropic's sandbox runtime. Anthropic puts the whole Claude Code process inside that boundary, because the sandboxed Bash tool alone leaves file tools, MCP servers and hooks outside it. The options below are from Anthropic's sandbox environments page, plus one row of ours.

OptionWhat it isolatesWorth knowing
Sandboxed Bash toolBash, PowerShell and Monitor commandsNot enough alone for unattended runs
Sandbox runtimeThe whole Claude Code processA beta research preview
Dev containerThe development environmentNeeds Docker. Anthropic's example has a default-deny firewall
Custom containerThe development environmentNeeds Docker. You set the network rules
Virtual machineA full operating systemThe strongest separation, with its own kernel
Cloud sessionsAn Anthropic-managed VMNeeds a Claude subscription. No bypass option
A separate always-on computerThe agent's mistakes, away from your laptopWhatever you sign in to on it stays reachable

If you only use Claude Code and your work lives on GitHub, start with Anthropic's cloud sessions. Anthropic's security page says its proxy holds the GitHub credential, and the session VM gets only a short-lived one scoped to that session. Its permission modes page lists no bypass option for cloud sessions. A plain computer, ours included, makes no such promise.

For Codex, OpenAI has its own cloud. Its approvals page describes the older Codex Cloud (Legacy) as isolated OpenAI-managed containers whose agent phase runs offline by default, and it points to other pages for the current one.

What does Hivra run Claude Code and Codex with?

By default, Chat runs Claude Code with the skip flag and Codex with its bypass flag. The Permissions setting on the agent's Manage tab narrows both to Limited or Read-only. The Claude Code session tab and the Codex session tab start the CLI with no permission flags.

Permissions settingClaude CodeCodex
Full access (the default)claude -p with --dangerously-skip-permissionscodex exec with --dangerously-bypass-approvals-and-sandbox
LimitedKeeps the skip flag, adds --disallowedTools Bash--sandbox workspace-write
Read-onlyDrops the skip flag--sandbox read-only

That table comes from Hivra's code. We haven't run a deletion or prompt-injection test against a Hivra computer, so none of it is a safety result.

You'll find it under Permissions on the Manage tab, and it applies from the next message. It shows only for Claude Code and Codex, and only on computers recent enough to support it. The session tabs are different: the CLI starts there with no flags, so you get its own default for its version and your account. The Terminal tab is a plain shell where you type your own flags.

Limited removes the Bash tool for Claude Code. Anthropic's tool docs say Monitor commands follow the same rules as Bash, but we haven't tested what a Limited agent can still run, so treat Limited as less access and don't count on it as a lock on every shell command. Read-only drops the skip flag and sets no permission mode, so the run starts in whatever mode Claude Code picks for its version. For a claude -p run that's Manual in sessions that fetch feature flags. In sessions that don't, it's auto on v2.1.285 or later and Manual before that (permission modes). In a Manual run with nobody there to answer, Anthropic's headless docs say requests that would prompt are denied, while reads and a built-in set of read-only commands still run. As for what a Read-only agent can still change, that's untested.

Chat runs as a regular user on the computer, not as root, which is the condition Anthropic sets for starting the flag on Linux. Don't read it as a limit. We haven't checked what that account can change, and on a computer launched for a Claude Code or Codex agent, Hivra's own instructions to the agent say it has sudo. Hivra pins the CLI version on its computers, so it can trail the newest release. Run claude --version in the Terminal tab and compare it with the version numbers in this guide.

In Chat's default setting, no prompt stands between the agent and a command. The computer around it is the boundary. Anthropic's own example for unattended runs is claude -p with the flag inside an isolated environment. Whether a Hivra computer holds up as one, we haven't tested. It's a separate machine from your laptop. How much that protects depends on what you sign in to there.

What does a separate computer not protect?

Anything you sign in to on it. A computer of its own keeps a mistake off your laptop. An agent with full access can still reach every login, key and repository you put there.

Anthropic says the same about containers. With the skip flag on, a dev container doesn't stop a malicious project from exfiltrating anything accessible inside it, including the Claude Code credentials in ~/.claude (Anthropic, dev containers). OpenAI says the same about Codex credentials. Both tell you to use trusted repositories only.

On Hivra, the Claude or ChatGPT login you use sits on the computer, and Hivra's admins can reach the host machines these computers run on. We're saying nothing, one way or the other, about outbound traffic limits or credential isolation on a Hivra computer. Assume the agent can reach whatever you put on it.

So sign in with only what the job needs. Anthropic advises repository-scoped or short-lived tokens. Deploy keys, cloud credentials and production access shouldn't be on that computer at all. Try it on a throwaway repository first.

How do I limit the damage when Claude Code runs with the prompts off?

Give it less to break. Work on a branch, keep secrets off the machine, and add deny rules, because deny rules still block in bypass mode and allow rules do nothing there.

--disallowedTools takes deny rules on the command line. A bare tool name such as Edit removes that tool from Claude's context, and a scoped rule such as Bash(rm *) leaves the tool and denies only matching calls. Anthropic's CLI reference notes that Bash rules match a command as written, so a deny rule narrows what the agent does and doesn't make it safe. In claude -p runs, --max-turns and --max-budget-usd cap a run too, and they work in print mode only (CLI reference).

On Hivra, the Permissions setting on the agent's Manage tab (Limited or Read-only) cuts what a Claude Code or Codex agent can do. For Codex, --sandbox workspace-write suits unattended work that can stay inside the workspace. Plain habits help too: commit before a long run and read the diff after it.

Why does Claude Code still ask for permission with the flag on?

Because a few checks survive it. Ask rules still prompt. So do rm and rmdir aimed at a critical path: the filesystem root, top-level folders, your home directory, your working directory and its parents. In a terminal that prompt has a two-minute countdown, then Claude Code denies the command (v2.1.281 or later). And if permissions.blockReadsOutsideWorkingDirectories is on, some reads outside the working directory prompt even in bypass mode (v2.1.257 or later).

Sometimes the mode just isn't there. Administrators can block it with permissions.disableBypassPermissionsMode. On Linux and macOS, Claude Code refuses to start with the flag as root or under sudo unless it spots a recognised sandbox. VS Code and the desktop app each need their own toggle, a session you steer from the Claude app through Remote Control can't pick Bypass or Auto, and cloud sessions don't offer it at all.

You also can't switch it on halfway. A session that started without bypass can't enter it. --allow-dangerously-skip-permissions adds it to the Shift+Tab cycle without turning it on. A bypassPermissions value in a project or local settings file has no effect on v2.1.257 or later, and the session starts in Manual mode. Before that, a project file could turn it on.

One last quirk. In a claude -p run with the flag, the few calls that would still prompt get denied instead. The first interactive start shows a warning dialog, and accepting it stores skipDangerousModePermissionPrompt in ~/.claude/settings.json. claude -p never shows that dialog.

Which setup should I pick to run Claude Code or Codex without prompts?

On a laptop with no sandbox, use auto mode. For Claude-only work on GitHub repositories, start with Anthropic's cloud sessions. For Claude Code or Codex on a computer that stays on, a Hivra computer fits, as long as you accept that anything you sign in to on it stays reachable.

You wantPickBecause
A laptop, and you're watchingManual or autoManual asks before commands and edits. Auto has a classifier review commands and anything beyond reads and edits in your working directory
A laptop and a long taskAuto, or the sandbox runtimeAuto needs no container. The sandbox runtime isolates the whole process
A throwaway repository in your own containerThe flag plus a default-deny firewallIt's the setup Anthropic's example dev container uses
Claude Code only, work on GitHubAnthropic's cloud sessionsAnthropic's proxy holds the GitHub credential, and there's no bypass option
Codex only, in the cloudOpenAI's own cloudOpenAI's approvals page covers the older cloud's isolation and links to the current one
Claude Code or Codex on a computer that stays onA Hivra computerIt stays on and runs the official CLI with your own login. Whatever you sign in to on it stays reachable

A Hivra computer fits the last row only. In the other five rows, the pick in the middle column is the better call. Paid plans start at $9.99 a month for 2 vCPU and 4 GB of RAM, stay on without being paused for inactivity, and come with a 7-day money-back guarantee on card payments. The $19.99 plan is 4 vCPU and 8 GB of RAM. You can start from the Claude Code agent page or the Codex agent page, and the pricing page has the rest. For the wider question of leaving an agent running while you're away, read is it safe to leave an agent running unattended. Keeping Claude Code running 24/7 covers the staying-on part. Hivra is independent and is not affiliated with Anthropic or OpenAI.

Common questions

What does --dangerously-skip-permissions do?

It starts Claude Code in bypassPermissions mode and turns off the permission prompts, so commands and file edits run without asking, including writes to protected paths such as .git and .claude. Deny rules still block, ask rules still prompt, and allow rules do nothing. Anthropic says to use it only in isolated environments such as containers and VMs.

Is --dangerously-skip-permissions safe?

Not by itself. Anthropic's docs say bypass mode offers no protection against prompt injection or unintended actions, so the container, VM or sandbox around it is the protection. Isolation cuts the impact of a mistake, and an agent with network access can still leak what it can read. A separate computer keeps the damage off your laptop. Whatever you sign in to on it is still within the agent's reach.

What is the difference between auto mode and --dangerously-skip-permissions?

The flag turns the prompts off and puts nothing in their place. Auto mode has a second model review commands and anything beyond reads and edits in your working directory. It blocks actions that go beyond your request, aim at unrecognised infrastructure or look driven by hostile content. Anthropic says auto mode reduces prompts without guaranteeing safety, and its March 2026 post gave error rates for it. For the flag, its docs say to use it only inside a container or VM. Auto mode doesn't come with that rule.

Can you run --dangerously-skip-permissions as root?

Not on Linux or macOS. Claude Code refuses to start with the flag as root or under sudo, unless it detects a recognized sandbox. Anthropic's advice is to run the container, VM or sandbox runtime as a non-root user.

Why does Claude Code still ask for permission with --dangerously-skip-permissions?

A few checks still run with the flag on. Ask rules still prompt, and rm or rmdir aimed at a critical path such as your home directory still asks, with a two-minute countdown in a terminal on v2.1.281 or later. An administrator can block the mode, and a session that started without the flag can't switch it on later. In a claude -p run, the few calls that would still prompt are denied instead.

Does --dangerously-skip-permissions ignore deny rules?

No. Deny rules block in every mode, bypass included, and ask rules still prompt. Allow rules have no effect in bypass mode, so an allowlist that leaves out a command doesn't stop it. Deny rules are the rule type to add when you run the flag. Ask rules help too if someone's there to answer the prompt.

Can I turn on bypass permissions in the middle of a session?

Only if you started the session with it enabled. You can't enter bypassPermissions from a session that started without it. Launching with --allow-dangerously-skip-permissions adds it to the Shift+Tab cycle without turning it on. A bypassPermissions value in a project or local settings file has no effect on v2.1.257 or later, and the session starts in Manual mode.

Does claude -p skip permissions?

No. claude -p runs Claude Code without a terminal and doesn't turn permission checks off by itself. With nobody there to answer, Anthropic's headless docs say requests that would prompt are denied. For a fully unattended run, Anthropic's docs show claude -p with --dangerously-skip-permissions inside a container, a VM or the sandbox runtime.

What is the Codex equivalent of --dangerously-skip-permissions?

--dangerously-bypass-approvals-and-sandbox, which OpenAI also accepts as --yolo. It turns off approvals and the sandbox together, and OpenAI says to use it only inside an externally hardened environment. Codex also splits the controls: --sandbox takes read-only, workspace-write or danger-full-access, and --ask-for-approval takes on-request or never. For unattended local work that can stay inside the workspace, OpenAI suggests --sandbox workspace-write.

Does Claude Code Desktop support skip permissions?

Yes, behind a toggle. The desktop app's mode selector shows Bypass permissions only when Allow bypass permissions mode is on in Desktop settings, which you set yourself on Pro and Max. On Team and Enterprise, organization policy decides. VS Code has its own Allow dangerously skip permissions toggle, and Anthropic's cloud sessions don't offer bypass at all.

What does Hivra run Claude Code and Codex with?

By default, Chat runs Claude Code with --dangerously-skip-permissions and Codex with --dangerously-bypass-approvals-and-sandbox. The Permissions setting on the agent's Manage tab narrows that to Limited or Read-only from the next message. The Claude Code session tab and the Codex session tab start the CLI with no permission flags. Hivra is independent and is not affiliated with Anthropic or OpenAI.

Give your agent a computer that stays on.

From $9.99/mo. Bring your own AI key. 7-day money-back guarantee on card payments.

Start Now