Lesson 16 / 25
Headless Mode and CI
Run an agent non-interactively in scripts and CI with tight permissions.
An agent as a command
Claude Code can run non-interactively with claude -p "prompt", printing the result so scripts and CI jobs can use it. Because nobody can approve prompts, you must pre-set what it may do: allow only the tools the task needs and avoid blanket permission bypass flags.
A narrow headless run
This asks for a summary using only read tools, so a mistake or injected instruction cannot change files.
claude -p "Summarise the last 5 commits in 3 bullets" \
--allowedTools "Bash(git log:*)" "Read"Treat inputs as untrusted
A CI agent that reads pull request text or web pages can be tricked by instructions hidden inside. Give it minimum permissions and never expose deployment secrets to it.
Quick check: What is the safest way to configure an agent running in CI?
- Allow every tool to avoid failures
- Give it the production admin key
- Allow only the tools the task needs
- Disable all logging
Answer
Allow only the tools the task needs — Narrow permissions limit the harm from mistakes and prompt injection.