Content Quality: Clear News structure, 668 words (News range 400-1200), neutral tone, includes an explicit 'What We Don't Know' section. Subject is an Anthropic product and the reviewer is a Claude model; Anthropic's claims were not credited on trust and every quote was checked against the snapshots.
Source Verification: Read all three snapshots from disk (gunzip; sha256 of decompressed content matches manifest for each). source-0.html.gz (code.claude.com changelog, 3.99 MB): contains the 2.1.284 entry (September 28, 2026) with the verbatim line 'Changed interactive terminal and VS Code sessions to start in auto mode when no permission mode is configured, on every plan and provider; permissions.defaultMode still overrides it'. 2.1.283 (September 25, 2026) contains 'Changed interactive sessions on third-party providers or with telemetry off to start in auto mode when no permission mode is configured; permissions.defaultMode still overrides it'. 2.1.285 (September 29, 2026) contains 'Changed claude -p and Python Agent SDK sessions on third-party providers or with telemetry off to start in auto mode when no permission mode is configured, like interactive sessions; --permission-mode still overrides it'. All three entries confirmed under the correct version headings; article's wording and dates match. source-1.html.gz (permission-modes docs): 'a second model, the classifier, reviews actions instead of you' verbatim; 'A separate classifier model reviews actions before they run, blocking anything that escalates beyond your request, targets unrecognized infrastructure, or appears driven by hostile content Claude read' (article splices the quoted fragment accurately); 'if the classifier blocks an action 3 times in a row or 20 times total, auto mode pauses and Claude Code resumes prompting'; 'By default, the classifier doesn't review rm and rmdir removals targeting a critical path'; Manual fallback when auto unavailable; permissions.disableAutoMode = 'disable' in managed settings for Team/Enterprise; 'Auto mode reduces permission prompts but does not guarantee safety'; opt-out via permissions.defaultMode 'default' in ~/.claude/settings.json; 'auto' in project .claude/settings.json or settings.local.json 'doesn't take effect'; first-time notice shown. 'only on Pro, Max, and Team plans' verbatim. All confirmed. source-2.html.gz (Simon Willison, 8 Aug 2026 link post): 'they are making it the default setting for new sessions in most Claude Code plans starting on August 14th', 'Only 13.6% of the humans refused that harmful action. Auto mode would have blocked 89% of those actions.', 'In this evaluation, none of the 720 attack attempts succeeded against Claude Fable 5, Opus 5, or Sonnet 5 running auto mode.' (a quote of Anthropic's own article, 72 scenarios by Trajectory Labs), 'Confirmation fatigue is real', 'that still leaves 11% of cases where auto mode would not have prevented the action', and 'I'd like to see more independent confirmation of this' (article's 'to see more independent confirmation of this' is a verbatim fragment). All confirmed. The article correctly frames the safety evaluations as Anthropic-published and relayed by Willison, and flags that they cover the earlier rollout. Caveat: the evaluations are known only second-hand via Willison; the Anthropic evals article itself is not a cited source. Nothing in the article rests on the GitHub issue the writer excluded.
Factual Accuracy: All quotes verbatim; versions and dates match the changelog. Second imprecision: the article says the Pro/Max/Team default 'began on August 14, according to Simon Willison', but Willison's Aug 8 post only announces a planned start ('starting on August 14th') and says 'most Claude Code plans'; the post cannot confirm it began. Docs also tie the earlier default to v2.1.228 or later (macOS/Linux/WSL) rather than a date. Filed as a clarification.
Overall Assessment: Accurate, verbatim-sourced, properly attributed and neutral. Two minor imprecisions are honestly covered by a short corrections record; no headline, summary or lead depends on an unsupported fact (the headline and lead are directly backed by the 2.1.284 changelog entry).