Claude Code YOLO mode (--dangerously-skip-permissions) with a safety net

What skipping permissions actually turns off in Claude Code, Codex CLI and Gemini CLI, what has gone wrong in practice, and how to run agents unattended without betting your project on it.

Updated October 2026

claude --dangerously-skip-permissions starts Claude Code in bypassPermissions mode: tool calls run without asking, including writes to protected paths like .git. Anthropic says to use it only in containers or VMs. It's dangerous on your own machine because nothing stops a bad command and Claude's checkpoints can't undo what shell commands did.

Last checked: October 2026. Flags and mode names are taken from each tool's current docs, linked below.

This page explains what YOLO mode does in Claude Code, Codex CLI and Gemini CLI, the incidents that show why it's risky, how to prevent damage, and how to recover when prevention wasn't enough.

What --dangerously-skip-permissions does

In Claude Code, --dangerously-skip-permissions is equivalent to --permission-mode bypassPermissions. The docs describe the mode as one that "disables permission prompts and safety checks so tool calls execute immediately, including writes to protected paths." Protected paths include .git, .vscode, .husky, .claude, shell startup files such as .bashrc and .zshrc, and .npmrc.

A few things still hold in bypass mode:

  • Deny rules still block. Allow rules have no effect, but deny rules apply "in every mode, including bypassPermissions."
  • Explicit ask rules still prompt, as do tools that need user interaction.
  • rm and rmdir on a critical path still prompt. Critical paths include the filesystem root, top-level directories like /usr, your home directory, and your working directory and its parents.
  • It refuses to run as root. On Linux and macOS, Claude Code won't start in this mode as root or under sudo, except inside a recognized sandbox.
  • First run shows a warning you have to accept. Administrators can block the mode with permissions.disableBypassPermissionsMode: "disable".

The docs are blunt about the rest: "bypassPermissions offers no protection against prompt injection or unintended actions."

Claude Code permission modes

Claude Code has six permission modes. Shift+Tab cycles through them in the CLI.

ModeWhat runs without askingBest for, per Anthropic
default (shown as Manual)Reads onlySensitive work, unfamiliar code
acceptEditsReads, file edits, and common filesystem commands like mkdir, touch, mv, cpIterating on code you're reviewing
planReads, plus classifier-approved commands when auto mode is availableExploring before changing anything
autoEverything, with a background classifier checking each actionLong tasks, prompt fatigue
dontAskReads and pre-approved tools; anything else is deniedLocked-down CI and scripts
bypassPermissionsEverythingIsolated containers and VMs only

Auto mode is the middle ground most people want. From Claude Code v2.1.283 it's the built-in starting mode for interactive terminal and VS Code sessions. A separate classifier model reviews actions before they run and, by default, blocks things like curl | bash, sending sensitive data to external endpoints, production deploys and migrations, force push, git reset --hard, terraform destroy, and "irreversibly destroying files that existed before the session." Anthropic still warns that auto mode "does not guarantee safety." It needs a supported model, and organizations can turn it off.

YOLO mode in Codex CLI and Gemini CLI

Codex CLI. Codex separates two settings: a sandbox mode (read-only, workspace-write, danger-full-access) and an approval policy (on-request or never). The default Auto preset is workspace-write with on-request: Codex edits and runs commands in the workspace, and asks before writing outside it or using the network. The YOLO flag is --dangerously-bypass-approvals-and-sandbox, alias --yolo, which OpenAI's docs label "No sandbox; no approvals (not recommended)." codex exec --full-auto is now a deprecated alias; use codex exec --sandbox workspace-write.

Gemini CLI. Gemini CLI's --approval-mode takes default, auto_edit, yolo or plan. The old -y / --yolo flag still works but is deprecated in favour of --approval-mode=yolo. YOLO can only be turned on from the command line, not from settings.json, and the configuration reference says "Sandbox is enabled when using --yolo or --approval-mode=yolo by default." Admins can block it with security.disableYoloMode.

Claude CodeCodex CLIGemini CLI
YOLO flag--dangerously-skip-permissions--yolo (--dangerously-bypass-approvals-and-sandbox)--approval-mode=yolo (--yolo deprecated)
Sandbox while in YOLONot automatic; Anthropic says run in a container, VM or sandbox runtimeOff: the flag removes the sandboxOn by default
Middle-ground modeauto (classifier) or acceptEditsAuto preset (sandboxed, asks to leave it)auto_edit
Admin kill switchdisableBypassPermissionsModeManaged configurationsecurity.disableYoloMode

Is Claude Code dangerous? What has actually gone wrong

With prompts on and a sensible mode, Claude Code is no more dangerous than any tool that runs commands as your user. With prompts off, the risk is real and documented:

  • The s1ngularity supply-chain attack (August 2025). Malicious versions of the Nx build package ran a post-install script that invoked installed AI CLIs with --dangerously-skip-permissions, --yolo and --trust-all-tools to search the filesystem for wallets, keys and tokens. Wiz reports over a thousand valid GitHub tokens leaked. The script also appended sudo shutdown -h 0 to ~/.bashrc and ~/.zshrc. The lesson: a YOLO flag is a capability any process on your machine can use.
  • A home directory deleted (December 2025). A user on r/ClaudeAI reported that Claude Code ran rm -rf tests/ patches/ plan/ ~/, and the trailing ~/ wiped most of their home folder. This is a user report, covered by Gigazine and discussed on Hacker News; whether permissions were bypassed or the command was approved without reading isn't confirmed.
  • Gemini CLI overwrote a user's files (July 2025). Asked to move files into a new folder, Gemini CLI's directory creation failed and each move overwrote the previous file. The AI Incident Database records that attempts to revert failed.
  • Replit's agent deleted a production database (July 2025). Not a CLI, but the same failure: during a code freeze, Replit's agent ran destructive commands against a live database. Fortune reported the loss, and Replit said it was rolling out separate development and production databases in response.

Two patterns repeat: a destructive shell command the user didn't read, and an action that reached something outside the project.

How to run an agent without prompts more safely

1. Isolate it. Anthropic's guidance is to "always run --dangerously-skip-permissions sessions inside a container, a VM, or the sandbox runtime." Its reference dev container runs as a non-root user with a default-deny firewall (init-firewall.sh). OpenAI publishes a secure devcontainer for Codex. Both warn the same thing: inside the container, a malicious project can still exfiltrate whatever the container can read, including the agent's own credentials. Don't mount ~/.ssh or cloud credentials. Details in sandbox vs undo.

2. Prefer a classifier or allowlist over a blanket bypass. In Claude Code, auto mode or acceptEdits plus the Bash sandbox removes most prompts without removing every check.

3. Write deny and ask rules for the things you can't take back. These apply in every mode:

{
  "permissions": {
    "deny": ["Bash(git push --force *)", "Read(./.env)", "Read(~/.ssh/**)"],
    "ask": ["Bash(git push *)", "Bash(npm publish *)", "Bash(terraform *)"]
  }
}

Deny and ask rules also match subcommands inside && chains, subshells and loops, per the permissions docs.

4. Commit before you start. A clean working tree turns most local disasters into git restore ..

Recovery: the piece YOLO mode is missing

Prevention reduces how often things go wrong. It doesn't help once they have. Here's what each agent can put back after a bad unattended run:

  • Claude Code: /rewind restores files Claude's edit tools changed, but "checkpointing does not track files modified by Bash commands." An rm, mv or a script that rewrote twenty files stays as it is. See what /rewind can't undo.
  • Codex CLI: its ghost-snapshot /undo was removed in April 2026, so recovery is git.
  • Gemini CLI: checkpointing is off by default and only triggers before file-writing tools.

How the other agents compare is in AI coding agent checkpoints compared.

How Darce handles it

Darce is an open-source terminal agent (not part of Claude Code) built around reversibility. Before every step that can change your project, it snapshots the working tree, so /undo also reverses files a shell command created, changed or deleted, in a git repository. That changes the YOLO trade-off: if local mistakes can be taken back, the prompts only need to cover what can't.

Darce's approval modes:

ModeEdits and buildsNetwork, installs, unknown commandsDestructive (rm -rf, sudo, force-push)
auto (default)runaskask
askaskaskask
planblockedblockedblocked
fullrunrunrun

In auto, project edits and builds run without prompts because /undo can reverse them. Commands that reach outside your machine wait: deploy, migrate, seed and release scripts, database clients, git push, publishes. The prompt says /undo can't reverse them. Scripts like npm run x get a second look from a fast classifier that reads the real script line, and that check can only make Darce more careful. Destructive commands can never be "always allowed."

full asks for nothing, which makes it Darce's YOLO mode. Use it where you would use --dangerously-skip-permissions: in a container, on a branch, with nothing remote reachable that you care about. /undo still restores local files there, but no undo reaches a deploy or a push.

Limits to know: undo history lasts for the session, gitignored files like node_modules aren't snapshotted, and outside a git repo /undo only covers Darce's own edits.

Sources

Frequently asked questions

What does --dangerously-skip-permissions do in Claude Code?

It starts Claude Code in bypassPermissions mode, so tool calls run without prompts, including writes to protected paths like .git. Deny rules, explicit ask rules and rm on critical paths such as your home directory still apply.

Is Claude Code YOLO mode safe?

Anthropic says to use bypassPermissions only in isolated environments such as containers or VMs, and that it offers no protection against prompt injection. Auto mode, which has a classifier review actions, is the safer way to reduce prompts.

What is the difference between auto mode and bypass permissions in Claude Code?

Auto mode runs without routine prompts but a classifier blocks risky actions like force push, production deploys and curl | bash. Bypass permissions skips the checks entirely.

What is the Codex CLI equivalent of --dangerously-skip-permissions?

--dangerously-bypass-approvals-and-sandbox, alias --yolo. It removes both the sandbox and approval prompts, and OpenAI's docs mark it not recommended.

Does Gemini CLI --yolo use a sandbox?

Yes, by default. Gemini CLI's configuration reference says the sandbox is enabled when using --yolo or --approval-mode=yolo. The --yolo flag is deprecated in favour of --approval-mode=yolo.

Can I undo what Claude Code did in YOLO mode?

/rewind restores files Claude's edit tools changed, but not files changed by Bash commands like rm or mv. Use git to recover the rest, and commit before unattended runs.

Related guides