Outside-directory paths found in command substitutions and redirections now raise their own ask prompt instead of being blocked silently.
A new helper builds a dedicated 'ask' decision for paths outside the working directories that are found via read-checking of nested commands and redirections (command substitution and redirection targets), separate from the general blocked-command message, when permissions.blockReadsOutsideWorkingDirectories would otherwise block them silently.
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
When you set it in a project's `.claude/settings.json` or `.claude/settings.local.json`, Claude Code honors it under the same [workspace trust rule as hooks in settings files](/docs/en/permissions#what-runs-before-you-trust-a-folder). Whil…memory see the edit
* Fixed Bash commands with two directory changes, a subshell, or a `cd`+`git` chain skipping the prompt under `permissions.blockReadsOutsideWorkingDirectories` in bypass and auto modechangelog see the edit
Anthropic's documentation has since written up permissions.blockReadsOutsideWorkingDirectories, on Claude Code changelog.
Added a one-time prompt in auto mode before the first file read outside the working directories, with the option to block such reads…