5 hacks
Turn on `/sandbox` so OS-level filesystem and network boundaries replace many per-command Bash prompts.
Enable auto mode so a classifier approves safe tool calls and blocks destructive ones — fewer prompts without a full permission bypass.
Add a deterministic PreToolUse hook that rejects destructive shell patterns before Claude can run them.
Instead of guessing which commands to allowlist or giving up and skipping permissions entirely, let Claude read your past sessions and propose the rules you have already been approving.
Use /permissions to allowlist read-only and trusted commands so you stop mindlessly clicking Approve.