Many more shell commands are recognised as read-only, so you get fewer needless permission prompts.
What's wrong with this entry?
Command safety analysis gained substantially more data: a bigger read-only command set (cal, uptime, hexdump, numfmt and others), zsh and bash builtin lists, literal safe-command patterns for things like claude --help, node -v, ip addr, jq, cd, ls and find, and a split of find primaries from actions so that -delete, -execdir and -files0-from count as unsafe.
"--multi-turn-model": "string"
Strings lifted out of the shipped bundle, so the claim above can be checked against them.