What
When a cloud session runs tools on your machine through remote tool execution (a served call), Claude Code now adds deny rules under the source hostCredential. They block reading or changing:
- The connection's own credential, and the credential file named in
CLAUDE_CODE_HOST_CREDS_FILE. /proc/*/environon Linux, which exposes other programs' environment variables.- Keychain command-line tools:
securityon macOS andsecret-toolon Linux. - On Windows, Credential Manager, SecretManagement, PasswordVault and
runas /savecred, detected in Bash and PowerShell commands.
MCP tool inputs whose paths reach these locations are refused, or sent to you for approval when the path cannot be vouched for.
When the server flag tengu_violin_lining is on, two more things apply:
- Personal credentials are added (
personal_credential), including~/.ssh,~/.aws,~/.config/gcloud,~/.azure,~/.kube,~/.gnupg,~/.config/gh,~/.config/glab-cli,~/.netrc,~/.git-credentials,~/.npmrc,~/.pypirc,~/.pgpassand more. A refused call gets a message naming the file. sandboxAutoAllowSuspendedis set for served calls, so sandboxed commands from a cloud session no longer skip the permission prompt.
The flag counts as on unless the server sends false without an override. That includes when no value arrives or reading it fails. For this site's account and for an anonymous check, the flag server returned on, but no reading has been taken under this release yet.
Why
This keeps a cloud-driven agent from reading or changing your saved logins and keys, even for a command you would otherwise allow.
tengu_violin_lining On for this account, and not off by defaultThe flag server returned on for the one account this site reads, and nothing in this release compiles it off by default. The compiled default is shown below, and says which it is when we cannot read one: a fifth of gates compile in a string or a number rather than on or off, and most published releases have no gate table behind them at all. No client can see what the server returns for your account.
This account: on · anonymous baseline: on · compiled default in v2.1.283: on
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.283. It isn't a statement about your account. What a flag value here can and cannot tell you
It is not clear who can currently let cloud sessions run tools on their machine.