Sandboxed command network allow/deny lists now default to enabled if the controlling flag can't be read
The check that decides whether to register network allow/deny lists for sandboxed commands (commandNetworkListsOffered) now looks at a flag called tengu_flickering_rain, and falls back to enabling the lists (true) if that flag can't be read. Previously this fell back to a different flag that defaulted to off.
If the flag lookup ever fails or is unavailable, sandboxed commands will now have network allow/deny lists registered by default instead of going without them.
tengu_flickering_rain On for this account, and not off by defaultThe flag server returned on for the one account this site reads, and nothing in this release compiles it off by default. The compiled default is shown below, and says which it is when we cannot read one: a fifth of gates compile in a string or a number rather than on or off, and most published releases have no gate table behind them at all. No client can see what the server returns for your account.
This account: on · anonymous baseline: on · compiled default in v2.1.271: on
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.271. It isn't a statement about your account. What a flag value here can and cannot tell you
A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
The `tengu_flickering_rain` gate itself currently reads off for this site's account and for the anonymous baseline, but no reading has been…