{"version":"2.1.281","anchor":"auto-mode-safety-check-dialog-now-auto-denies-on-a-timer-te","canonical_anchor":"auto-mode-safety-check-dialog-now-auto-denies-on-a-timer-te","heading":"Safety-check prompts for dangerous removals now deny themselves after a timeout","tier":"soon","area":"Auto Mode","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/auto-mode-safety-check-dialog-now-auto-denies-on-a-timer-te","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Safety-check prompts for dangerous removals now deny themselves after a timeout\n\nPrompts for dangerous commands like rm in auto or bypass mode deny after 2 minutes by default and stop appearing after 3 unanswered\n\n**What**\n\nSome commands, such as dangerous removals with `rm`, trigger a safety check that asks you before running. This release adds a timer to those prompts and new handling in the auto and bypass permission modes.\n\n- The safety check behind dangerous removals, `dangerousRemoval`, is now marked `autoModeDeny`. In auto mode, or plan mode with auto active, such a check is treated as needing a person rather than something auto mode can approve.\n\n- Instead of falling back to a plain question, Claude Code either denies the command outright or shows a permission dialog with an auto-deny window (`autoDenyWindow`). If you do not answer before the window ends, the command is denied.\n\n- In `bypassPermissions` mode, the same checks can now show this timed dialog when an interactive dialog is available. Before, there was no dialog path. If `showDialog` is off or no dialog can be shown, the command is denied immediately.\n\n- After a set number of unanswered prompts in one session, Claude Code stops showing the dialog and denies straight away. The count resets when you allow or deny a prompt.\n\n- These prompts no longer offer an \"always allow\" rule when the reason cannot be approved automatically (`suppressAlwaysAllowRule`).\n\n- The behaviour is controlled by the server config `tengu_splendid_horizon`. Nothing has been read about that config for this release. Its built-in fallbacks are `enabled: true`, `showDialog: true`, `timeoutMs: 120000` (2 minutes) and `maxDialogTimeouts: 3`.\n\n- The server can set the timeout between 5,000 and 3,600,000 milliseconds, and a value outside that range is not used as given. A server `enabled` value counts only when it arrives in the config payload.\n\n- Setting the environment variable `CLAUDE_CODE_DISABLE_DANGEROUS_RM_TIMEOUT` turns the feature off.\n\n**Why**\n\nA dangerous-command prompt in an unattended session no longer waits forever. It resolves to a deny, which is the safe outcome, and after three unanswered prompts the session stops asking. If you would rather such prompts wait for you indefinitely, set `CLAUDE_CODE_DISABLE_DANGEROUS_RM_TIMEOUT`.\n\n- Area: Auto Mode\n- Tier: Nothing to try yet\n- Useful: 4\/5\n- Signal: 4\/5\n- Present in the build but not switched on"}