What it is
The dangerous-rm safety check for bash commands can now be extended with an extra custom check
Not Anthropic's. This is the line from the earliest changelog entry here that named it, v2.1.273.
Presence across releases
0The miner has never read a build containing this name. It is here because a changelog entry of ours names it, which is evidence that it existed and not evidence of which releases carried it. The inventory starts at v2.1.138 and everything older than that was never mined.
First cited
1The earliest release whose published evidence quoted tengu_bash_dangerous_rm_too_complex was v2.1.277, 18 Sep 2026. That is the oldest release this project wrote about it, so it is a floor on the name's age and not the release that introduced it. It is not a presence reading: which builds carried the name is the table above.
Gate readings
0No release here has a gate table behind it for this flag. Most published releases have none at all: the readings exist only for versions the pipeline captured flag state on.
Names beside it
Every feature flag in the inventory starting tengu_bash, up to twelve of them.
tengu_bash_allowlist_strip_allNo description from anybody. v2.1.138
tengu_bash_ast_too_complexBash's 'too complex to check' read-block guard now applies via a general table covering more refusal reasons, not just one hardcoded case never mined
tengu_bash_command_clamp_deniedIf a clamped agent's permission check crashes, the shell command is denied rather than allowed. never mined
tengu_bash_security_check_triggeredNo description from anybody. never mined
tengu_bash_task_ackBackgrounded shell commands may return a structured task record instead of raw output. never mined
tengu_bash_task_deliveredFinished background tasks now report whether their output was spliced back in or lost. never mined
tengu_bash_tool_command_executedBash/PowerShell telemetry and sandbox checks now track whether the user typed the command directly. never mined
tengu_bash_tool_command_failedBash tool telemetry now records a detailed breakdown of each command's shape never mined
Read out of the published npm bundle release by release, and out of Anthropic's own documentation as this site captured it. Nothing on this page is a description anybody here wrote about what the feature flag does. All feature flags.