Lesson 16 / 25

Headless Mode and CI

Run an agent non-interactively in scripts and CI with tight permissions.

An agent as a command

Claude Code can run non-interactively with claude -p "prompt", printing the result so scripts and CI jobs can use it. Because nobody can approve prompts, you must pre-set what it may do: allow only the tools the task needs and avoid blanket permission bypass flags.

A narrow headless run

This asks for a summary using only read tools, so a mistake or injected instruction cannot change files.

claude -p "Summarise the last 5 commits in 3 bullets" \
  --allowedTools "Bash(git log:*)" "Read"

Treat inputs as untrusted

A CI agent that reads pull request text or web pages can be tricked by instructions hidden inside. Give it minimum permissions and never expose deployment secrets to it.

Quick check: What is the safest way to configure an agent running in CI?

  • Allow every tool to avoid failures
  • Give it the production admin key
  • Allow only the tools the task needs
  • Disable all logging
Answer

Allow only the tools the task needs — Narrow permissions limit the harm from mistakes and prompt injection.