Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.236 Home All releases olderv2.1.235 v2.1.237newer
Claude Code v2.1.236

Deny rules match batched tools by the original tool name

Use it now
Useful4 Signal3
Permissions

A disallowedTools rule now also blocks the batched wrapper around that tool.

disallowedTools
What

A disallowedTools entry naming a tool now also blocks the batched wrapper around that tool. Previously a rule written against the original name did not stop the wrapped form.

Details
  • Wrapper tools carry the name of the tool they wrap, and the permission check treats a match on that name as a match on the wrapper.
  • The same lookup is applied to the plan-mode and read-only tool sets, so a wrapper cannot be used to run something those modes exclude.
  • Applies whenever a batching tool is present; there is no flag.
Evidence

if (a.underlyingV1ToolName !== void 0 && t.has(a.underlyingV1ToolName)), if (n.underlyingV1ToolName && w0(t, { name: n.underlyingV1ToolName }, r))

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.236 →