Fetching from the wire…
Public story · 2026-08-10 · high
His real worry is malicious packages the model trusts, a threat 72 scripted scenarios don't test for.
Why now: Willison posted this assessment on August 8, right as Anthropic frames auto mode as the fix for Claude Code's constant approval prompts.
Simon Willison endorsed Anthropic's case for auto mode in Claude Code on August 8, then refused to call it safe.
The gap matters for teams running Claude Code unattended. Anthropic's case for auto mode rests on 72 scripted test scenarios. Willison's worry is the one those scenarios can't catch: a hostile package with no human watching.
He agrees with the underlying argument. "Asking humans to click OK every few steps is clearly not going to result in safe behavior," he wrote. But he won't sign off on the fix. "I would love to believe that Anthropic have indeed solved this problem for Claude Code users," he wrote, and left it there.
Willison's specific worry is malicious third-party packages that look credible to the model, the exact failure scripted scenarios can't surface. My read: a convincing fake isn't something you can write a test case for before you've seen it.
He's also predicted a coding-agent security disaster sometime in 2026, and he wants outside verification before accepting Anthropic's numbers at face value. He's not alone in that instinct.
Each link below shares sources, entities, or timing with this story.
This one hit my inbox and I had to read it twice. Anthropic announced a partnership with SpaceXAI for the entire Colossus 1 data center in Memphis. 220,000 NVIDIA GPUs. 300+ megawatts. That's the largest single compute acquisition by any AI lab. Full stop. But the part that ma...
Willison published his AI Engineer World's Fair conversation with Anthropic's Cat Wu and Thariq Shihipar, covering Claude Code, Claude Tag, and Fable. Primary-source practitioner conversation with the people who actually build the thing, rather than secondary coverage of a pre...
On July 16 there was a wave of backlash calling the Bun Zig→Rust rewrite unreviewed AI slop. On July 19, Simon Willison went and checked. (Simon Willison) Jarred Sumner claimed Claude Code v2.1.181 and later ship the Rust port. Willison verified it independently rather than ta...
Three independent sources — Simon Willison at the Pragmatic Summit, blog.tedivm.com's coding agent guide, and Anthropic's 2026 Trends Report — converged in March 2026 on the same conclusion: the highest-leverage skill in AI-assisted development is no longer prompt engineering...
Anthropic shipped Fable 5 on June 9. Willison spent ~5.5 hours stress-testing it: slow and expensive, but it handled everything he threw at it, including agentic coding. (Simon Willison) The tell that it's a real working model and not a benchmark queen: because it post-dated A...
Anthropic shipped cross-session messaging for Claude Code on August 7, macOS and Linux, version 2.1.224 or higher. Two new tools: ListAgents discovers other active sessions on your machine, SendMessage delivers text to one by name. Messages between sessions on the same machine...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.