Your deny and ask rules now apply to artifacts pulled automatically by a watching session.
What's wrong with this entry?
When a session started with --watch-artifact pulls an artifact with no user prompt behind it, having the artifact tool enabled is no longer enough on its own: matching deny or ask permission rules for that tool now block the read. Previously this path returned allowed outright.
- Only reached when the artifact read surface is enabled in the first place; prompt-driven reads are unchanged.
promptless
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.234
--watch-artifactnow fails fast in remote sessionsBoth mention watch
-
v2.1.236
Artifact watch text now says when comment replies are not armed
Both mention watch
-
v2.1.238
Artifact watches are described as paused, not stopped
Both mention watch