Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.227 Home All releases olderv2.1.226 v2.1.228newer
Claude Code v2.1.227

Command clamps deny rather than fall open

You'll notice
Useful3 Signal2
Subagents

If a clamped agent's permission check crashes, the shell command is denied rather than allowed.

What

If the permission check for a clamped agent throws, the Bash call is denied, not run, with the reason "bashCommandClamp fail-closed: permission check crashed". Shell surfaces the clamp cannot inspect, including PowerShell, are denied outright with a message telling the model to use the clamped Bash forms instead.

Details
  • Each denial emits a tengu_bash_command_clamp_denied event carrying the number of clamp groups in force.
Evidence

tengu_bash_command_clamp_denied

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.227 →