What's wrong with this entry?
Claude is now informed about the user's configured permission deny rules and instructed to block circumvention attempts.
- The system prompt now includes a section listing all active deny rules
- Claude is instructed to block actions that achieve the same effect via a different tool — e.g., using
python -c,sed -i,cat >, heredocs, or similar to write a file that an Edit/Write deny rule covers - Only non-internal deny rules are surfaced (rules starting with a specific internal prefix are filtered out)
New function builds deny rule text: "User Deny Rules: The user has configured these permission deny rules..." — search for "User Deny Rules"
Strings lifted out of the shipped bundle, so the claim above can be checked against them.