Under the hood
Internal function swap for the check that skips path-restricted commands from whole-tool allow rules
What
A check used when evaluating shell command permission rules now calls a different internal function to determine whether a broad 'allow this whole tool' rule should be ignored for commands that are restricted to specific paths.
Why
This is an internal implementation change to how permission rules are evaluated; the finding does not say whether it alters which commands are allowed or blocked in practice.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
Whether this changes actual permission behavior or is a pure refactor is not stated.