Sub-agent spawns are refused when the Bash command restriction couldn't be enforced.
What's wrong with this entry?
Two new checks on sub-agent spawns. If the host has remapped Bash or the related exec tools to different names, the clamp cannot be guaranteed on that path and the spawn is refused. If the spawned agent's tool set contains no Bash at all, the spawn is refused rather than running an agent whose clamp does nothing.
- a third guard refuses schema-mode spawns whose combined disallow list denies the StructuredOutput tool, which that mode needs
agent() bashCommandClamp under a shell toolAlias
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.234
Another forged control tag is escaped in subagent output
Both mention subagent
-
v2.1.234
Spawned processes get
--flag=valuewhen the value looks like a flagBoth mention subagent
-
v2.1.235
New error for delegating to a subagent without naming one
Both mention subagent