What
In auto mode, a classifier, an automatic safety check, decides whether each tool use may run without asking you. When the SendMessage tool forwards a message to Claude Desktop, the forwarded call was checked a second time.
- The forwarded call now carries
desktopForwardToolUseIdwhen the original call went through the auto-mode check. The id is removed if the input is anything other than the exact session_id and message pair. - A call with that id is allowed without another check if the classifier already allowed the SendMessage and the input is unchanged.
- This shortcut is refused if:
- the permission mode changed while the call was waiting
- custom
soft_denyorhard_denyclassifier rules exist - the call would need to leave the sandbox
- working-folder or blocked-path concerns apply
- If a hook holds back Desktop's messaging tool, nothing is sent. Claude is told to send it again when ready, because a forwarded send cannot be resumed later.
Why
Forwarding a message to Claude Desktop no longer pays for the same safety check twice. It is quicker and costs less, while any change in mode, input or rules still sends the call through the full check.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
What Claude Desktop does with the forwarded ID is not clear.