I've tested an autonomous hacker on real products over the past month, [1] and it's very capable. Concretely, I could: Hijack accounts at a major bank and log in as other users. Bypass authorization in a major AI lab's product and access other users&
Running Claude Code with --dangerously-skip-permissions is dangerous, as the name suggests. If an attacker gains control through prompt injection, they can steal your keys, exfiltrate your data, and execute arbitrary code. Claude Code on the web, Anthropic's async and hosted version, always dangerously skips permissions. To