Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.222 Home All releases olderv2.1.221 v2.1.223newer

Shell tools get an explicit worktree isolation root

You'll notice
Useful3 Signal0
Sandbox

Agent commands now have a concrete worktree boundary, so escapes get blocked with a clearer log line.

What

Bash and shell execution paths now take an isolationRoot so the checks that keep agent commands inside their worktree have a concrete boundary to compare against.

Details
  • isolationRoot is resolved from the agent worktree, falling back to the session worktree path.
  • Used by the checks that block commands whose cwd escapes the isolation worktree, and those that redirect git into the shared checkout.
  • Blocked commands log with isolationRoot= in the message and report tengu_agent_worktree_cwd_escape_blocked.
  • The field itself is new in this build.
Evidence

isolationRoot

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.222 →