{"version":"2.1.281","anchor":"read-only-bash-classifier-gains-an-offline-estimate-mode-and","canonical_anchor":"read-only-bash-classifier-gains-an-offline-estimate-mode-and","heading":"Read-only Bash classifier gains an offline-estimate mode and a new argv check","tier":null,"area":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/read-only-bash-classifier-gains-an-offline-estimate-mode-and","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Read-only Bash classifier gains an offline-estimate mode and a new argv check\n\nThe read-only Bash check gains an offline-estimate mode and now rejects commands with some kinds of arguments\n\n**Unclear.** The finding does not say what the new argument check tests for or when the offline mode is used.\n\n**What**\n\nClaude Code can decide that a shell command is read-only, meaning it only looks at things and changes nothing. The part that decides this changed in two ways:\n\n- It takes a new `offlineEstimate` option. When set, it skips three checks: looking up allowed environment variables, probing for bare repositories or `.git` redirects, and checking the sandbox's working folder.\n\n- It now rejects a command when later arguments, or the target of a `<` redirect (which feeds a file into the command), fail a new check.\n\n**Why**\n\nThe new argument check makes it harder for a command to be treated as read-only when it should not be. The offline mode gives a quicker estimate without the checks that look at the system."}