{"version":"2.1.281","anchor":"auto-mode-can-hold-locally-auto-allowed-shell-commands-for-a","canonical_anchor":"auto-mode-can-hold-locally-auto-allowed-shell-commands-for-a","heading":"Auto mode can hold locally auto-allowed shell commands for a server-side classifier","tier":"notice","area":"Auto Mode","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/auto-mode-can-hold-locally-auto-allowed-shell-commands-for-a","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Auto mode can hold locally auto-allowed shell commands for a server-side classifier\n\nIn auto mode, shell commands allowed locally by sandbox or read-only rules can now be held for a server-side classifier to review\n\n**Unclear.** The finding does not explain what a \"served call\" is or how the `arbiter` modes are chosen.\n\n**What**\n\nIn auto mode, Claude Code can now take a shell command that local rules had already allowed and turn it back into a question. The shown reason is \"Auto mode held this command for the server-side classifier to review\". A classifier here is a check run on Anthropic's servers that decides whether a command looks safe. Before this change, a command allowed by those local rules simply ran.\n\nThis happens only when all of these are true:\n\n- The original allow came from the sandbox rule (the sandbox is a restricted environment commands run inside) or from the read-only rule (commands that only look at things and change nothing).\n\n- The call is not a served call.\n\n- The auto-mode classifier mode is `arbiter` or `arbiterWithLocalFallback`.\n\nThe held request records which local rule it overrode in a `reroutedFrom` field, set to `sandbox` or `readOnly`. For commands made of several parts, a new helper looks through each part's result to find the rule that produced the allow.\n\n**Why**\n\nWith those classifier modes, a local allow is no longer the final word for these commands. Some commands that used to run straight away may now pause for review.\n\n- Area: Auto Mode\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 3\/5"}