{"version":"2.1.283","anchor":"cmdexe-rdrmdirdelerase-on-protected-paths-blocked-in-pow","canonical_anchor":"cmdexe-rdrmdirdelerase-on-protected-paths-blocked-in-pow","heading":"PowerShell guard blocks cmd \/c rd, rmdir, del and erase aimed at drive roots or the home folder","tier":"notice","area":"Windows","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283\/e\/cmdexe-rdrmdirdelerase-on-protected-paths-blocked-in-pow","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283","markdown":"### PowerShell guard blocks cmd \/c rd, rmdir, del and erase aimed at drive roots or the home folder\n\nOn Windows, cmd.exe delete commands run from PowerShell are now blocked when they target a drive root, a folder directly under one, or the home folder\n\n**What**\n\nWhen Claude runs a PowerShell command that launches cmd.exe (Windows' older command prompt), for example `cmd \/c rd \/s ...`, Claude Code now checks what that inner command deletes. The check blocks the command when it would remove a protected path: a drive root, a folder directly under a drive root, or the home folder.\n\n- It covers the delete commands `rd`, `rmdir`, `del` and `erase` started through `cmd \/c`, `cmd \/k` or `cmd \/r`.\n\n- It reads the command line the way cmd.exe would, including carets, quotes, `--%`, nested `start` and `cmd` calls, and folder changes made with `cd` or `pushd` earlier on the same line.\n\n- It checks each target again after expanding cmd's `%NAME%` variables and PowerShell's `$var` variables.\n\n- Setting the environment variable `CLAUDE_CODE_DISABLE_POWERSHELL_CMD_RM_DENY` turns the check off. The variable was also added to two lists of environment variables Claude Code recognises.\n\n- The rule also stands aside when the server-delivered flag `tengu_curious_lake` comes back explicitly false.\n\n**Why**\n\nClaude Code already guarded against deleting these paths, but a destructive `cmd \/c rd \/s` wrapped in PowerShell could get past those protections. The new check closes that gap on Windows and applies unless someone turns it off.\n\n- Flag `tengu_curious_lake`: Not enough to say (read for one account on one subscription tier against v2.1.283; this account: no value returned, anonymous baseline: no value returned, compiled default: on) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: Windows\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}