{"version":"2.1.280","anchor":"host-only-native-tool-speculation-path-added-but-currently-d","canonical_anchor":"host-only-native-tool-speculation-path-added-but-currently-d","heading":"Speculative permission evaluation threaded into native tool execution","tier":"internal","area":"Tool Execution","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280\/e\/host-only-native-tool-speculation-path-added-but-currently-d","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280","markdown":"### Speculative permission evaluation threaded into native tool execution\n\nTool execution now carries a 'speculation' object through permission checks, laying groundwork for host-only native tool handling\n\n**Unclear.** The finding states this path is currently dead code, so it's unclear when or how it will take effect.\n\n**What**\n\n- Tool execution now builds a `speculation` object (carrying `honourHostAllowRules`) for certain tools, using a new `claude-code.hostOnlyNativeTool` marker that flags some native tools as host-only.\n\n- The core per-call permission-decision function now accepts this `speculation` argument and passes it down into the classifier and host-allow-rule check.\n\n**Why** This wires speculative, host-only handling into the permission system, though the path does not yet appear to be active for any tools.\n\n- Area: Tool Execution\n- Tier: Under the hood\n- Useful: 2\/5\n- Signal: 3\/5"}