PromptArmor:Claude Dynamic Workflows 子代理权限与文档不符
Claude Dynamic Workflows Inaccurate Permissions Docs
PromptArmor 报告 Claude Dynamic Workflows 生成的子代理会继承用户会话的命令审批模式,与官方文档所称“始终运行在 acceptEdits 模式”不符。
原文给出文档与实际行为不一致的具体验证细节和组织侧关闭方法,读者可据此检查自身 Claude Code 配置。
Subagents spawned by Claude Dynamic Workflows inherit command approval modes from the user’s session, despite documentation explicitly stating “subagents the workflow spawns always always run in acceptEdits mode… regardless of the user’s session mode”.
Note: ‘acceptEdits’ is a restricted mode that allows only limited file editing without user approval.

As a result, subagents spawned by workflows can execute with unintended elevated permissions, such as in Auto or BypassPermissions modes. This exposes a risk of untrusted shell command execution, MCP invocation, network egress, edits outside the sandbox, and edits to sensitive protected file paths.
This has been validated on the latest version of Claude Code, Version 2.1.168. Claude Dynamic Workflows will be enabled by default for all users as of June 8, 2026.
Get alerts when Claude's human-in-the-loop settings change
How Organizations Can Disable Dynamic Workflows
Organizations can disable access to dynamic workflows by setting "disableWorkflows": true in:
Organization settings > Claude Code > Managed settings (settings.json)
Or, by disabling workflows in:
Organization settings > Claude Code > toggle off Workflows
Dynamic workflows can also be disabled at the role level by navigating to:
Organization settings > People > Roles > edit a role or create a new one > Capabilities > Claude Code > disable Workflows.
来源:PromptArmor:Threat Intelligence · promptarmor.com