Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.281 ·

Auto mode can hold locally auto-allowed shell commands for a server-side classifier

In auto mode, shell commands allowed locally by sandbox or read-only rules can now be held for a server-side classifier to review

You'll notice Improvements
JSON All of v2.1.281
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
Auto ModeArea: what it touches
ImprovementsKind: in v2.1.281,
ImprovementsSection of the release
What

In auto mode, Claude Code can now take a shell command that local rules had already allowed and turn it back into a question. The shown reason is "Auto mode held this command for the server-side classifier to review". A classifier here is a check run on Anthropic's servers that decides whether a command looks safe. Before this change, a command allowed by those local rules simply ran.

This happens only when all of these are true:

  • The original allow came from the sandbox rule (the sandbox is a restricted environment commands run inside) or from the read-only rule (commands that only look at things and change nothing).
  • The call is not a served call.
  • The auto-mode classifier mode is arbiter or arbiterWithLocalFallback.

The held request records which local rule it overrode in a reroutedFrom field, set to sandbox or readOnly. For commands made of several parts, a new helper looks through each part's result to find the rule that produced the allow.

Why

With those classifier modes, a local allow is no longer the final word for these commands. Some commands that used to run straight away may now pause for review.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe finding does not explain what a "served call" is or how the `arbiter` modes are chosen.

See this entry in the whole of v2.1.281 →

Feedback