What
A command substitution is a piece of a shell command, written as $(...) or in backticks, that is replaced by another command's output when it runs. A recursive rm (-r or -R) whose target is entirely such output now always stops for your approval. The message says "Dangerous rm operation detected: the target is the output of a command substitution ($(...) or backticks) and cannot be checked before the command runs." It tells you to run the substitution first and then remove the literal paths it prints.
- Permission rules cannot auto-allow this prompt.
- Paths like
${VAR:-$(cmd)}are now unwrapped before the check. - The check for a substitution at the end of a path now also handles
/..endings. - Setting the
CLAUDE_CODE_DISABLE_SUBSTITUTION_RM_PROMPTenvironment variable skips the prompt. So does a server value settingtengu_iridescent_bootto false. Nothing has been read abouttengu_iridescent_bootortengu_bash_dangerous_rm_too_complexyet.
Why
Claude Code cannot know in advance what such a command will delete. Commands like rm -rf $(find ...) now wait for you even if you have broad allow rules.
tengu_iridescent_boot Not enough to sayNothing here resolved what this flag was doing on this version, so nothing here should be read as on or off.
This account: no value returned · anonymous baseline: no value returned · compiled default in v2.1.281: on
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.281. It isn't a statement about your account. What a flag value here can and cannot tell you
The finding names `CLAUDE_CODE_DISABLE_SUBSTITUTION_RM_PROMPT` but does not say how it affects this prompt.
Fixed a recursive rm whose target is only command-substitution output, such as rm -rf "$(pwd)", running unprompted in auto and…
New in this build: tengu_iridescent_boot