What
Running a tool call on an attached machine (such as the user's own computer, connected to a cloud session) used to be compiled out entirely. It is now controlled by the environment variable CLAUDE_CODE_REMOTE_TOOLS_FORWARD. When it is true:
- Tools get an optional
_hostinput field naming the attached machine to run the call on. Leaving it out runs the call in the session's own environment, the default. Input clean-up now keeps_hoston Bash, Edit and Write calls. - Calls naming a machine are checked. File and search tools only pass when the call can actually be forwarded. Edit (errorCode 14) and Bash (errorCode 11) reject a call that names a machine but was not forwarded to it, and tell Claude to omit the field.
- The Bash tool description gains a "# Machines" section telling Claude to route commands to an attached machine with a per-call parameter, and never to sleep or poll for a machine that has gone offline. This section also needs a second check to pass. The stock Bash and Write descriptions captured under this release are unchanged.
- Transcript processing now handles
tool_host_result_linesattachments, which were hardcoded off before. - The transcript sanitiser brackets a key named
result_fromlike other reserved names, so tool output cannot pass itself off as that marker. - The auto-mode classifier prompt gains a section, "## Calls served by an attached machine". It says output from calls marked
"_host"orresult_fromis the user's private data from another machine. Sending that data to a network destination, git remote or external service from the session's own environment is judged as cross-machine data movement under Data Exfiltration.
The variable has to come from the real process environment: a settings file cannot turn it on. It is also stripped from the environment that child processes inherit.
The guard for incoming remote-control messages changed too. guardedFamilies() now switches hook and plugin forwarding off outright. Before, these were decided by CLAUDE_CODE_DISABLE_HOOK_FORWARDING, CLAUDE_CODE_DISABLE_PLUGIN_FORWARDING, CLAUDE_CODE_REMOTE_SESSION_ID and CLAUDE_CODE_ENTRYPOINT. Remote tools are on only when CLAUDE_CODE_REMOTE_TOOLS_FORWARD is true and CLAUDE_CODE_REMOTE_TOOLS_SESSION_CHANNEL is not false. With forwarding on, incoming messages also pass a session-channel check that can drop them.
Why
This is the first build in which Claude can be told to run Bash, Read, Write, Edit, Grep or Glob on another machine the user attached. The safety rules were extended with it, so data fetched from the user's machine is treated as private. None of it applies unless the process environment sets the variable. Hook and plugin forwarding over the remote-control channel no longer follows the old variables.
What uses the machine name to route the call, and what normally sets the variable, is not clear.
New in this build: CLAUDE_CODE_REMOTE_TOOLS_FORWARD