Can Claude's auto permission policy stop a prompt injection?
The auto permission policy, shipped on 10 September 2026, has the Claude Managed Agents server run, deny or pause each tool call. It assesses tool results, fetched pages and MCP responses without taking instructions from them. It does read user.message events as your intent, so relayed end-user text can get a call allowed that would otherwise be denied.
5 min read