A tool call is a single action Claude takes, such as running a command or editing a file. Claude Code now contains the part that lets your own machine receive tool calls forwarded from a Claude Code session running in the cloud, and decide what to do with them. It uses a fixed profile for a personal machine. Under it:
- Foreground only: commands run in the foreground, from the pinned project folder.
- No credentials: credential environment variables are removed.
- Time limit: each command may run for up to 45 seconds.
- Sandbox: a command is sandboxed when that folder's settings sandbox it.
- Approvals: you are asked to approve in the session, and the machine's own rules and hooks still apply.
When a call is not simply run, the answer comes back in a fixed format with an outcome of refused, failed, needs approval, in progress or acknowledged. It includes messages for Claude such as "Nothing was run." and "Do not retry in a loop." The code also handles a repeated call being replayed, caps how many calling sessions it keeps track of, deals with approvals that arrive too late, and runs a second automatic check on requests that need approval.
This is a security boundary. A cloud session can run tools on your own computer, and these are the rules for what your machine refuses and why.
What lets a machine start serving these calls was not traced, so whether this is active is unknown, as is whether the code is new or was…