{"version":"2.1.281","anchor":"read-only-command-check-rejects-tilde-arguments-for-ss-style","canonical_anchor":"read-only-command-check-rejects-tilde-arguments-for-ss-style","heading":"Read-only command check rejects tilde arguments for ss-style commands","tier":"notice","area":"Permissions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/read-only-command-check-rejects-tilde-arguments-for-ss-style","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Read-only command check rejects tilde arguments for ss-style commands\n\nRead-only command checks now treat any argument containing `~` as unsafe for commands using flags like `--socket` and `--family`\n\n**Unclear.** The finding does not say what the reordered or replaced safe-command entries change.\n\n**What**\n\nClaude Code has a list of commands it treats as read-only, meaning it can run them without asking you first. For one such command, the one that accepts the flags `-f`, `--family`, `-A`, `--query` and `--socket`, any argument that contains a `~` is now treated as not safe. A flag is an option written after a command, like `--socket`.\n\nThe extra entries added to the safe-command list were also reordered or replaced.\n\n**Why**\n\nIn practice, a command of this kind that includes `~` in an argument now goes through the normal permission check instead of running automatically.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}