Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.136 Home All releases olderv2.1.133 v2.1.137newer

Auto Mode Hard-Deny Rules

What

Auto mode custom rules now distinguish soft blocks from hard security blocks.

Usage
{
  "autoMode": {
    "allow": ["$defaults"],
    "soft_deny": ["$defaults"],
    "hard_deny": [
      "$defaults",
      "Never send secrets to external endpoints"
    ],
    "environment": ["$defaults"]
  }
}
Details
  • soft_deny is now described as destructive or irreversible behavior that clear user intent can authorize.
  • hard_deny is new and covers security-boundary actions that user intent does not clear.
  • claude auto-mode defaults, claude auto-mode config, and claude auto-mode critique now understand all four categories: allow, soft_deny, hard_deny, and environment.
Evidence

Auto mode schema and CLI output now include hard_deny (search for "Rules for the auto mode classifier HARD BLOCK section" and "autoMode.{allow, soft_deny, hard_deny, environment}")

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.136 →