Tools reference changedtools-reference
Nearest release: v2.1.289, published 9 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 4 Oct 2026 06:11 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 4 Oct 2026 06:37 UTC.
Upstream edited
Recorded here
Lines+11added
Lines−0removed
From line
435
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits52to this page, all time
### Bash deny rules also turn off the PowerShell tool
The whole hunk
from line 435, old and new numbered
/
from line 435
435435
436436Claude Code spawns PowerShell with `-ExecutionPolicy Bypass` at process scope only, so `.ps1` scripts and module imports work on default Windows installs without changing the machine's policy. Process-scope bypass doesn't override Group Policy `MachinePolicy` or `UserPolicy`, so enterprise policies still apply. To respect the machine's effective execution policy instead, set `CLAUDE_CODE_POWERSHELL_RESPECT_EXECUTION_POLICY=1`.
437437
438### Bash deny rules also turn off the PowerShell tool
439
440On Windows with Git Bash installed, denying Bash also turns the PowerShell tool off for the session. This applies to scoped rules such as `Bash(git push *)` as well as a bare `Bash`, and to rules from one of your settings files or `--disallowedTools`. Claude Code does this because a `Bash` rule doesn't restrict the PowerShell tool, which has [its own permission rules](/docs/en/permissions#powershell). With PowerShell left on, Claude could run there what your rule denies in Bash.
441
442To keep the PowerShell tool on alongside a Bash deny rule, do either of these:
443
444* Set `CLAUDE_CODE_USE_POWERSHELL_TOOL=1` in your environment or in the `env` block of a settings file, as shown in [Enable the PowerShell tool](#enable-the-powershell-tool).
445* Add a scoped [`PowerShell` permission rule](/docs/en/permissions#powershell) to a settings file, such as a `PowerShell(git push *)` deny rule.
446
447Without one of these, a scoped Bash deny rule leaves the Bash tool available, and Claude Code turns PowerShell off without a warning. A rule that removes the whole Bash tool leaves Claude with no shell tool for the session.
448
438449### Shell selection in settings, hooks, and skills
439450
440451Three additional settings control where PowerShell is used:
No line in this hunk matches that.