If a clamped agent's permission check crashes, the shell command is denied rather than allowed.
What's wrong with this entry?
If the permission check for a clamped agent throws, the Bash call is denied, not run, with the reason "bashCommandClamp fail-closed: permission check crashed". Shell surfaces the clamp cannot inspect, including PowerShell, are denied outright with a message telling the model to use the clamped Bash forms instead.
- Each denial emits a
tengu_bash_command_clamp_deniedevent carrying the number of clamp groups in force.
tengu_bash_command_clamp_denied
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.234
Another forged control tag is escaped in subagent output
Both mention subagent
-
v2.1.234
Spawned processes get
--flag=valuewhen the value looks like a flagBoth mention subagent
-
v2.1.235
New error for delegating to a subagent without naming one
Both mention subagent