You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.281,
ImprovementsSection of the release
What
Before running a shell command, Claude Code checks it with a classifier, a set of rules that decides whether the command needs your approval. One of these rules is a table of risky flags for each command. Flags are the options that start with --.
The git entry in that table no longer lists --git-dir or --work-tree. It still lists flags such as --upload-pack, --exec-path and --separate-git-dir. A separate pattern elsewhere still names --git-dir and --work-tree.
Two new helpers were also added:
One checks git commands for --git-dir and --work-tree, and handles git rev-parse specially.
One reads a command even when it starts with comments.
Why
These two flags point git at a different repository or working folder. They are now handled by a dedicated check rather than by the generic flag table.
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe finding does not say whether this changes which git commands ask for your approval.
Anthropic's release notes agreeFixed sandbox excludedCommands entries not matching git rev-parse --git-dir, programs named like shell builtins, and commit messages…