/cd into an untrusted folder now lists exactly what its settings would grant before you trust it.
What's wrong with this entry?
Changing into a directory Claude Code has not trusted now lists what that folder's .claude/settings.json and .claude/settings.local.json would give it: pre-approved tool permissions, extra accessible directories, hooks that run commands, and helpers that supply auth tokens or request headers. A second variant appears after the move when project grants are held back, ending with a note that they apply only if you trust the directory.
- The disclosure is built by reading the target's two settings files; if reading fails the error is logged and the prompt shows less rather than blocking the move.
- Wording such as "This directory configures hooks that run commands, declared in" is new in this build.
This directory configures hooks that run commands, declared in
Strings lifted out of the shipped bundle, so the claim above can be checked against them.