
Description
Full auto: nothing is asked, nothing is sandboxed, and project MCP servers are approved without prompting. Two of the three keys change something and one does not, which is worth saying because a posture that restates a default grants nothing while reading as though it grants a great deal. permissions.defaultMode is bypassPermissions, off the mode a session otherwise starts in, and enableAllProjectMcpServers is set where the vendor's own reference gives it *"Default: unset, so Claude Code asks you to approve each server"*. sandbox.enabled: false restates the documented default -- the same reference gives sandbox.enabled a default of false -- and is kept only so the posture survives the product changing it. The sandbox's own sub-keys are deliberately not set: autoAllowBashIfSandboxed, excludedCommands, allowUnsandboxedCommands, the network object and the rest govern a sandbox this posture switches off, so a permissive value there would be a key that reaches nothing. attribution and includeGitInstructions are left alone because they send something outward or shape the prompt rather than granting you a tool, and disableAllHooks is left alone because setting it removes a capability rather than granting one. Note that the sandbox key reaches nothing on native Windows -- this product's sandbox runs on macOS, Linux and WSL2 only -- so there the posture asks nothing and confines nothing because there was nothing to switch off. This is a setup posture -- keys in this product's own configuration file. It is not an execution profile and it grants no environment: what it changes is what the product asks you and which of its own tools exist, not what anyone is permitted to run. The key measurement behind this posture: the vendor's settings reference, read 2026-08-30, which documents the default of every key named here.