Why is auto mode blocking my command?
/permissions The Recently denied tab lists every classifier denial. Press r on one to retry it with your approval.
Answer
In auto mode a second model, the classifier, reviews each action, and Blocked by classifier means it judged this one unsafe, usually because it reached something it does not know is yours. Open /permissions, go to Recently denied and press r to retry with your approval. If the same destination keeps getting blocked, add it to autoMode.environment in your user settings; if a command should never be reviewed, add an allow rule. Three blocks in a row, or twenty in total, pause auto mode and bring the prompts back.
What it does
A denial shows up in three places, and they say different things. Match the one you saw.
bash denied by auto mode · Blocked by classifier · /permissions
The notice near the input box. It names the tool and the reason, and nothing else: the command itself is not in it. Blocked by classifier is the fixed text in most sessions from v2.1.208 on, because the classifier scores an action on an internal severity scale rather than writing an explanation. Some sessions run a classifier that does write a short reason (v2.1.193 and later); when you see one, read it as a hint about which destination or intent the classifier was missing. Which kind you get is not something you configure.
Claude is told about the block and tries another route, so the conversation does not stop here.
Denied by auto mode classifier
The line beneath the tool call in the transcript. This is the only place that carries the exact command or URL. If the call has been folded into a summary line such as Ran 3 shell commands, press Ctrl+O to open the transcript viewer, which expands it. The Recently denied tab lists the same call, but by the description Claude wrote for it, not by its input.
<model> is temporarily unavailable, so auto mode cannot determine the safety of <tool>
Not a verdict. The classifier's own request failed, and Claude Code blocked the action rather than guess. These denials do not appear under Recently denied, and the fix is to retry, not to reconfigure. The auto mode page covers the reasons the message names.
There is also a state without a message of its own. If the classifier blocks three actions in a row, or twenty in total, auto mode pauses and Claude Code goes back to prompting you. Approving the prompted action resumes auto mode. Any allowed action resets the run of three; the count of twenty lasts for the session. Neither number is configurable.
How to check
Find the call first, in the transcript. The text beneath it tells you which of two problems you have.
Text about the classifier itself, a model that is temporarily unavailable or a classifier error, means there was no verdict. Retry.
Denied by auto mode classifier means there was one. Then ask what the call was reaching for, because that decides the fix:
- a destination you need for the whole task, such as a package registry, an internal domain or a repository host
- a command you want to run without review from now on
- a one-off action you did intend
One more possibility is your own words. The classifier treats a boundary you stated in conversation, "don't push until I review", as a block signal, and it stays in force until you lift it in a later message. It can also be lost when compaction removes the message that stated it, so a boundary you rely on belongs in an ask or deny rule instead.
To see the rules the classifier is actually using, with your settings applied:
claude auto-mode configHow to fix it
A one-off you intended. Say so in your next message and let Claude retry, or open /permissions, go to Recently denied, press r on the action and leave the dialog. Claude Code tells the model it may retry that call.
A destination you need throughout. Add it to autoMode.environment. The entries are prose, written the way you would describe your infrastructure to a new engineer, and "$defaults" keeps the built-in ones:
{
"autoMode": {
"environment": [
"$defaults",
"Source control: github.example.com/acme-corp and all repos under it",
"Internal package registry: npm.corp.example.com"
]
}
}
The file matters: the classifier reads autoMode from ~/.claude/settings.json, managed settings and --settings, never from the two project files. Since v2.1.207 even .claude/settings.local.json is ignored, because a checked-in repository or a build step could otherwise inject its own allow rules. Run claude auto-mode config afterwards to confirm the entry took effect, or let /auto-mode-setup draft the entries from your project and recent sessions (Pro, Max and Team, v2.1.228 and later).
A command that should never be reviewed. Add a permissions.allow rule for it. Allow rules resolve before the classifier is consulted, so a matching call skips it entirely. The exceptions are writes to protected paths and removals aimed at a critical path, which reach the classifier even with a rule.
Repeated blocks on the same destination. Almost always missing context: the classifier does not know that host or bucket is yours. Add it to the environment. For a block you believe is plainly wrong, /feedback reports the false positive.
What not to do is switch to bypassPermissions. That removes every other check along with the one that annoyed you; the comparison shows what goes with it.
Example
The notice, the moment it appears:
bash denied by auto mode · Blocked by classifier · /permissions
Retry with your approval:
/permissions
Select Recently denied, press r on the action, and exit the dialog.
For a push that keeps getting blocked because the remote is your company's GitHub Enterprise host, the durable fix is the environment entry above, in ~/.claude/settings.json. For a push you want to approve by hand every time, even in auto mode, the mechanism is the opposite one, an ask rule:
{
"permissions": {
"ask": ["Bash(git push *)"]
}
}
That prompt appears in auto mode by design, and the classifier cannot approve past it.
Common mistakes
Switching to bypass after one block. A block is one action, and it is retryable. Bypass mode is not a bigger allow rule; it is the absence of review.
Putting autoMode in .claude/settings.json. Ignored, on purpose, and since v2.1.207 so is .claude/settings.local.json. Move the block to ~/.claude/settings.json.
Reading the classifier-outage message as a verdict. "Cannot determine the safety" means nobody decided. Retrying is right; reconfiguring is not.
Expecting the pause thresholds to be adjustable. Three in a row and twenty in total are fixed. If you keep hitting them, the environment is missing something, not the thresholds.
Looking for the command in the notice. It is only in the transcript, under the call. Ctrl+O if the call has been folded away.