Plausibly the auto mode classifier could catch the potential module shadowing attack and deny execution of Python from the untrusted directory.