Hooks now run with the shell prefix and environment of whichever side made the call.
What's wrong with this entry?
Hook processes now take their shell prefix, MCP shell prefix and MCP path from the context of the call that triggered them. For a call served from elsewhere, hooks run with the serving side's prefix and environment; locally the fallback is still the CLAUDE_CODE_SHELL_PREFIX environment variable.
- The base environment comes from the context, minus an explicit omit list, instead of the raw process environment.
- The context builder now takes the call's origin explicitly and derives its own-sources set from that origin's distrusted sources.
Hooks: a served call's hooks run without
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.247
Device hooks get a full child environment, and an untrustworthy shell prefix is dropped
Both mention shell prefix
-
v2.1.247
Hook inventory sent to a cloud worker includes the repo root
Both mention shell prefix