{"version":"2.1.281","anchor":"rm-r-on-a-command-substitution-target-now-always-asks-unle","canonical_anchor":"rm-r-on-a-command-substitution-target-now-always-asks-unle","heading":"rm -r on the output of a command substitution now always asks for approval","tier":"notice","area":"Permissions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/rm-r-on-a-command-substitution-target-now-always-asks-unle","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### rm -r on the output of a command substitution now always asks for approval\n\nCommands like rm -rf $(...) now always stop for approval, even with broad allow rules, unless an env var or flag turns this off\n\n**What**\n\nA command substitution is a piece of a shell command, written as `$(...)` or in backticks, that is replaced by another command's output when it runs. A recursive `rm` (`-r` or `-R`) whose target is entirely such output now always stops for your approval. The message says \"Dangerous rm operation detected: the target is the output of a command substitution (`$(...)` or backticks) and cannot be checked before the command runs.\" It tells you to run the substitution first and then remove the literal paths it prints.\n\n- Permission rules cannot auto-allow this prompt.\n\n- Paths like `${VAR:-$(cmd)}` are now unwrapped before the check.\n\n- The check for a substitution at the end of a path now also handles `\/..` endings.\n\n- Setting the `CLAUDE_CODE_DISABLE_SUBSTITUTION_RM_PROMPT` environment variable skips the prompt. So does a server value setting `tengu_iridescent_boot` to false. Nothing has been read about `tengu_iridescent_boot` or `tengu_bash_dangerous_rm_too_complex` yet.\n\n**Why**\n\nClaude Code cannot know in advance what such a command will delete. Commands like `rm -rf $(find ...)` now wait for you even if you have broad allow rules.\n\n- Flag `tengu_iridescent_boot`: Not enough to say (read for one account on one subscription tier against v2.1.281; this account: no value returned, anonymous baseline: no value returned, compiled default: on) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5"}