You'll noticeTier: how much it should matter to you
3Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.268,
ImprovementsSection of the release
What
Permission-request prompts now render the network allow-list (networkAllowHosts) for a pending command or tool, alongside the existing sandbox and tool-type information.
The bash-command permission dialog specifically now shows a hosts component next to the command description, driven by the tool call's networkAllowHosts data.
When a tool's input carries such a host allow-list, approving it now records the allowed domains (allowed_domains) against that tool use in telemetry, and the list is also attached to the classifier record.
Why
This lets you see exactly which network hosts a command or tool will be allowed to reach before you approve it, rather than approving blind, and gives better visibility into what was actually allowed after the fact.