Claude Code Auto Mode 'Gave No Verdict': Why Even pwd Gets Blocked
Bash, Edit and MCP calls all refused while Read still works. The auto mode safety check failed, not your command. What the error means, why it stops after ten, and four fixes from Anthropic's own docs.
If Claude Code suddenly refuses every shell command — even pwd — with this, you're not alone:
The server-side auto mode classifier gave no verdict (error), so auto mode cannot
determine the safety of Bash. This is a transient failure of the check, not a
judgment about the action: a later response may get a verdict.Starting on 28 September, three separate GitHub reports filed the same day collected dozens of "same here" replies across macOS, Linux, Windows and WSL, in the terminal, VS Code and the desktop app. The top one, #97854, describes every Bash call failing for several minutes, then recovering with nothing changed. Users kept reporting it on 29 and 30 September and into October.
The short version: your command was never judged. A safety check that runs before risky actions failed to answer — the auto mode classifier gave no verdict — and the CLI chose to block rather than run anything unchecked. Below is what that check is, why the failure looks so strange, and the four ways out.
What auto mode's classifier actually does
In auto mode, the CLI stops asking you to approve each action. Instead, as Anthropic's docs put it, "a separate classifier model reviews actions before they run, blocking anything that escalates beyond your request, targets unrecognized infrastructure, or appears driven by hostile content Claude read."
From v2.1.283, auto mode is the default starting mode for interactive terminal and VS Code sessions. That's why so many people met this error without ever choosing auto mode.
The detail that matters for this error is where the check runs. Recent versions ask Anthropic's servers to do it as part of the normal model request, instead of Claude Code making a separate classifier call. The docs call this server-side classifier review, and it's being rolled out across the direct Anthropic API, cloud providers and LLM gateways.
When the server returns its decision, that decision is final. When it returns nothing, the classifier gave no verdict, and the action is refused.
Why pwd is blocked but Read still works
This is the part that makes the error feel broken. Claude can still read your files, search the code and often edit, but ls fails.
It's by design. In auto mode's decision order:
| Action | Goes through the safety check? |
|---|---|
| Read tool, searches | No — auto-approved |
| File edits inside your working directory | No — auto-approved, except protected paths |
Read-only shell commands (pwd, ls, git log) | Yes, with server-side review — they wait for the check |
| Other shell commands, network calls, MCP tools | Yes |
The docs are explicit that "in a session with server-side classifier review, read-only and sandboxed shell commands wait for that review." So when the review fails, every Bash call fails with it, harmless or not. The Read tool, which never goes to the check, carries on.
If your file edits are blocked too, which two of the reports describe, check two things. Is the file outside the directory you started the session in? And is it under a protected path such as .claude/, .git/, .vscode/ or .mcp.json? Both of those always go to the check in auto mode.
The three messages, and what each means
One action blocked:
The server-side auto mode classifier gave no verdict (timed out), so auto mode
cannot determine the safety of <tool>.The word in brackets is the failure category, when one can be worked out — (timed out), (error) and so on. Before some retries, it waits; the spinner shows Auto mode check unavailable with a countdown, and Esc interrupts.
The turn stopped:
Auto mode is unavailable — the server returned no safety verdict for the last 10
responses, so Claude stopped. Send a message to try again, or switch out of auto mode.Ten responses in a row without a verdict ends the turn. In a non-interactive -p run, the run ends with an execution error. A subagent that hits the limit stops early, and the main session gets whatever it produced.
A different failure that looks similar:
<model> is temporarily unavailable (rate-limited), so auto mode cannot determine
the safety of <tool> right now. Wait a moment and then try this action again.This one comes from Claude Code's own classifier request rather than the server's review. The category can be (rate-limited), (overloaded), (server error), (timed out) or (connection failed). If timed out or connection failed keeps coming back, treat it as a network problem first — it's the same territory as 529 overloaded errors.
Four fixes, in the order I'd try them
1. Send another message
The official first step, and often enough. Sending a new message resets the count of failed responses. In the reports, most outages cleared on their own within minutes to tens of minutes. One commenter put a window of roughly 13:16–13:35 UTC on 28 September.
If you can, keep Claude busy with read-only work meanwhile. Reading and searching don't need the check.
2. Use Claude Code's own classifier instead of the server's
export CLAUDE_CODE_AUTO_MODE_SERVER=0
claudeThis tells the CLI to skip the server-side review and make its own classifier requests, the way it did before. It's documented, and a commenter on #97766 reported it as an effective workaround during the outage. Set it before starting the session, in your shell or in the env block of your settings file.
Three things to know first:
- It needs v2.1.281 or later on a direct Anthropic API connection. Earlier versions ignore it there.
- It can cost money, depending on your account. The server's checks are free. Claude Code's own classifier requests count toward token usage on Enterprise plans, Claude API accounts, and Amazon Bedrock, Google Cloud's Agent Platform and Microsoft Foundry.
- It's temporary. Anthropic's billing page says the variable "is a temporary setting and may be removed in a later release." Use it to get through an outage, not as permanent config.
To see which path a session is on, run /status. The Auto mode server row reads Enabled while the server is doing the checks, and Disabled once the session has fallen back to its own.
3. Switch out of auto mode
Press Shift+Tab to change permission mode. This was the most common workaround in the threads, and the one Anthropic's message itself suggests:
- Manual (
default) — you approve everything except reads. Slower, but immune to this error. - Accept edits — file edits and common filesystem commands like
mkdir,mvandcprun automatically. Other shell commands still ask you.
Several people reported switching to accept-edits for a few actions and then back to auto as a fix. That probably just coincided with the server recovering — there's no documented reason it would reset anything. But it's harmless.
4. If it never stops: check your gateway or proxy
If your traffic goes through an LLM gateway or company proxy (ANTHROPIC_BASE_URL points somewhere other than Anthropic), and the error keeps coming back when nobody else is reporting an outage, the gateway is the likely cause.
The docs name the behaviour precisely. A gateway that cuts streaming responses short, or rewrites them, means the safety results never arrive intact. The client then sees no verdict and blocks the action. The fix is on the gateway side: pass requests and responses through unchanged, including fields it doesn't recognise, such as safeguards on requests and safeguard_results on responses.
If you know your gateway can't do that, CLAUDE_CODE_AUTO_MODE_SERVER=0 is the documented setting for exactly this situation.
Why it blocks instead of asking you
The most-repeated request in the threads is the same one: if the check is down, fall back to asking me, don't refuse. It's a fair complaint. A blocked turn burns time, and one user pointed out that each failed attempt still spends a turn against their usage.
Claude Code's current behaviour is a deliberate fail-closed design. Its docs say it "denies the action rather than run it unreviewed." Anthropic doesn't spell out the reasoning there, but my reading is this: auto mode exists for people who aren't watching each action. Quietly downgrading to "ask" could just as easily mean an action sits waiting while nobody is there, or, in a non-interactive run, gets dropped without a decision.
You don't have to accept that default. The fixes above are the ways to choose a different trade-off for your own session.
The bigger picture: a check on every tool call is now a product category
This outage is a good example of something every agent builder will run into. Once a second model sits between the agent and every risky action, that model's uptime becomes your agent's uptime.
That pattern has just become its own kind of product. On 15 September, TypeSafe AI released Jev, a "decision model" that doesn't write text at all. You send it the current state and a set of typed questions, and it returns choices with probabilities, in tens to hundreds of milliseconds. LangChain's walkthrough uses it for precisely this job: classifying risky tool calls before they're taken, alongside a normal LLM doing the actual work.
Two cautions if you're tempted. Jev is in limited early access, and its headline claims — 40 to 200 times faster and 40 to 400 times cheaper than frontier models — are the company's own. Wikipedia notes that TypeSafe itself describes those figures as likely to sit at the high end of real-world results.
More importantly, a faster checker doesn't remove the problem this post is about. It moves it. Whatever you put in front of your tool calls, decide up front what happens when it doesn't answer — block, ask a human, or allow — and make that choice visible to the people running the agent. Claude Code made its choice and documented it. Most homegrown agent harnesses haven't made one at all.
Quick triage
- Is Read still working? Then the agent is fine and only the safety check is failing.
- Send another message. It resets the counter, and short outages clear on their own.
- Still failing? Restart with
CLAUDE_CODE_AUTO_MODE_SERVER=0(v2.1.281+), knowing it may bill classifier calls on API, Enterprise and cloud-provider accounts. - Need to keep moving right now?
Shift+Tabout of auto mode and approve actions yourself. - Happens constantly, and only for you? Check whether a gateway or proxy is truncating streamed responses.
Key takeaways
- 'Gave no verdict' means auto mode's safety check failed to answer — not that your command was judged unsafe.
- With server-side review, even read-only shell commands like pwd and ls wait for the check, which is why they fail while the Read tool keeps working.
- Ten responses in a row with no verdict stops the turn; sending a new message resets the count.
- CLAUDE_CODE_AUTO_MODE_SERVER=0 switches to Claude Code's own classifier (v2.1.281+), but it can bill tokens on API, Enterprise and cloud-provider accounts and is documented as temporary.
- A gateway that cuts streaming responses short causes the same error permanently. Any agent with a safety check in front of its tools needs a deliberate policy for when that check is down.
Frequently asked questions
What does 'the server-side auto mode classifier gave no verdict' mean?
In auto mode, a second model checks shell commands, network calls and other risky actions before they run. On many connections that check now happens on Anthropic's servers. 'No verdict' means the check failed to come back — it timed out, the response ended early, or it couldn't be read — so Claude Code refused the action rather than run it unchecked. It is not a judgement that your command was dangerous.
Why does Claude Code block pwd and ls but still let Claude read files?
The Read tool, searches and edits inside your working directory skip the classifier. Shell commands do not: in a session with server-side review, even read-only shell commands like pwd, ls and git log wait for the server's check. When the check fails, they are blocked along with everything else that goes through Bash.
How do I stop the auto mode classifier error?
Send another message, which resets the count. If it keeps happening, start Claude Code with CLAUDE_CODE_AUTO_MODE_SERVER=0 so it uses its own classifier requests instead of the server's check (requires v2.1.281 or later on a direct Anthropic API connection), or switch out of auto mode with Shift+Tab and approve actions yourself. If your traffic goes through an LLM gateway or proxy, check that it isn't cutting streaming responses short.
Does CLAUDE_CODE_AUTO_MODE_SERVER=0 cost more?
It depends on your account. Server-side checks are free. Claude Code's own classifier requests count toward token usage on Enterprise plans, Claude API accounts, and Amazon Bedrock, Google Cloud's Agent Platform and Microsoft Foundry. Anthropic describes the variable as temporary and says it may be removed in a later release.
If the gateway in step 5 is a company proxy, the same "something in the middle rewrote the traffic" problem is behind Claude Code's corporate-proxy SSL errors. Deciding what an agent is allowed to do unsupervised, and what happens when the guardrail itself goes down, is a large part of the agent work I do — see recent projects.
References
- Choose a permission mode — Claude Code docscode.claude.com · accessed 2026-10-05
- Error reference — Claude Code docscode.claude.com · accessed 2026-10-05
- Auto mode classifier request charges — Claude Code docscode.claude.com · accessed 2026-10-05
- Auto mode: server-side safety classifier intermittently returns no verdict (anthropics/claude-code #97854)github.com · accessed 2026-10-05
- Auto mode classifier unavailable blocks Bash/Edit calls (anthropics/claude-code #97766)github.com · accessed 2026-10-05
- How we built Claude Code auto mode — Anthropic Engineeringanthropic.com · accessed 2026-10-05
- Building a harness with Jev — LangChainlangchain.com · accessed 2026-10-05
- Jev (AI model) — Wikipediaen.wikipedia.org · accessed 2026-10-05
Last reviewed October 5, 2026
Tahir Nazir
Senior AI Engineer & Full-Stack Lead
5+ years shipping AI-powered products — RAG pipelines, agentic workflows, and MCP tooling. Top Rated on Upwork with a 100% job success score.
More about Tahir →Keep reading
New posts land here first. Follow along by RSS, or get in touch if you are building something similar.
Related articles
Claude Code 529 Overloaded: What It Retries For You, and What It Won't
A 529 isn't your usage limit and doesn't touch your quota. Claude Code already retried ten times before it told you. The useful question is which failures it retries automatically, which it deliberately doesn't, and the one environment variable that stops an unattended run dying on a transient capacity blip.TroubleshootingAI Engineering8 min readClaude Code Behind a Corporate Proxy: Why NODE_EXTRA_CA_CERTS Isn't the Fix
Unable to get local issuer certificate behind Zscaler or any TLS-inspecting proxy. Claude Code already trusts your OS certificate store by default — so the usual advice fixes it for some people and not others. The variable that actually decides is CLAUDE_CODE_CERT_STORE, and whether your runtime can read the OS store at all.TroubleshootingAI Engineering11 min readClaude Code Won't Start on Windows? Match the Error, Not the Guide
Raw mode is not supported, 'claude' is not recognized, 32-bit Windows, Exec format error on WSL1 — five different Windows startup failures that get treated as one problem. Each has a distinct cause and a distinct fix, and four of them aren't install failures at all.TroubleshootingAI Engineering8 min read