# Headless Mode and CI — Advanced Agent Workflows and Skills

Source: https://www.geekswithgeeks.com/en/agent-workflows/hooks-headless-ci

> Run an agent non-interactively in scripts and CI with tight permissions.

## An agent as a command

Claude Code can run non-interactively with `claude -p "prompt"`, printing the result so scripts and CI jobs can use it. Because nobody can approve prompts, you must pre-set what it may do: allow only the tools the task needs and avoid blanket permission bypass flags.

## A narrow headless run

This asks for a summary using only read tools, so a mistake or injected instruction cannot change files.

```bash
claude -p "Summarise the last 5 commits in 3 bullets" \
  --allowedTools "Bash(git log:*)" "Read"
```

## Treat inputs as untrusted

A CI agent that reads pull request text or web pages can be tricked by instructions hidden inside. Give it minimum permissions and never expose deployment secrets to it.

**Quiz:** What is the safest way to configure an agent running in CI?

- [ ] Allow every tool to avoid failures
- [ ] Give it the production admin key
- [x] Allow only the tools the task needs
- [ ] Disable all logging

*Answer:* Allow only the tools the task needs. Narrow permissions limit the harm from mistakes and prompt injection.
