Under the hoodTier: how much it should matter to you
2Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
Tool ExecutionArea: what it touches
Internal ChangesKind: in v2.1.280,
Internal ChangesSection of the release
What
Tool execution now builds a speculation object (carrying honourHostAllowRules) for certain tools, using a new claude-code.hostOnlyNativeTool marker that flags some native tools as host-only.
The core per-call permission-decision function now accepts this speculation argument and passes it down into the classifier and host-allow-rule check.
Why
This wires speculative, host-only handling into the permission system, though the path does not yet appear to be active for any tools.
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe finding states this path is currently dead code, so it's unclear when or how it will take effect.