{"version":"2.1.283","anchor":"remote-tools-forwarding-escapes-the-result-from-transcript-t","canonical_anchor":"running-tool-calls-on-an-attached-machine-host-moves-fr","heading":"Tool calls can be sent to an attached machine with _host when CLAUDE_CODE_REMOTE_TOOLS_FORWARD is set","tier":"use","area":"Remote Tools","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283\/e\/remote-tools-forwarding-escapes-the-result-from-transcript-t","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283","markdown":"### Tool calls can be sent to an attached machine with `_host` when CLAUDE_CODE_REMOTE_TOOLS_FORWARD is set\n\nWith CLAUDE_CODE_REMOTE_TOOLS_FORWARD set, tools gain a `_host` field for running on an attached machine, with new Bash guidance and classifier rules\n\n**Unclear.** It is not confirmed which part of Claude Code reads this cleaned transcript, or that preventing spoofed markers is the purpose.\n\n**What**\n\nRunning a tool call on an attached machine (such as the user's own computer, connected to a cloud session) used to be compiled out entirely. It is now controlled by the environment variable `CLAUDE_CODE_REMOTE_TOOLS_FORWARD`. When it is true:\n\n- Tools get an optional `_host` input field naming the attached machine to run the call on. Leaving it out runs the call in the session's own environment, the default. Input clean-up now keeps `_host` on Bash, Edit and Write calls.\n\n- Calls naming a machine are checked. File and search tools only pass when the call can actually be forwarded. Edit (errorCode 14) and Bash (errorCode 11) reject a call that names a machine but was not forwarded to it, and tell Claude to omit the field.\n\n- The Bash tool description gains a \"# Machines\" section telling Claude to route commands to an attached machine with a per-call parameter, and never to sleep or poll for a machine that has gone offline. This section also needs a second check to pass. The stock Bash and Write descriptions captured under this release are unchanged.\n\n- Transcript processing now handles `tool_host_result_lines` attachments, which were hardcoded off before.\n\n- The transcript sanitiser brackets a key named `result_from` like other reserved names, so tool output cannot pass itself off as that marker.\n\n- The auto-mode classifier prompt gains a section, \"## Calls served by an attached machine\". It says output from calls marked `\"_host\"` or `result_from` is the user's private data from another machine. Sending that data to a network destination, git remote or external service from the session's own environment is judged as cross-machine data movement under Data Exfiltration.\n\nThe variable has to come from the real process environment: a settings file cannot turn it on. It is also stripped from the environment that child processes inherit.\n\nThe guard for incoming remote-control messages changed too. `guardedFamilies()` now switches hook and plugin forwarding off outright. Before, these were decided by `CLAUDE_CODE_DISABLE_HOOK_FORWARDING`, `CLAUDE_CODE_DISABLE_PLUGIN_FORWARDING`, `CLAUDE_CODE_REMOTE_SESSION_ID` and `CLAUDE_CODE_ENTRYPOINT`. Remote tools are on only when `CLAUDE_CODE_REMOTE_TOOLS_FORWARD` is true and `CLAUDE_CODE_REMOTE_TOOLS_SESSION_CHANNEL` is not false. With forwarding on, incoming messages also pass a session-channel check that can drop them.\n\n**Why**\n\nThis is the first build in which Claude can be told to run Bash, Read, Write, Edit, Grep or Glob on another machine the user attached. The safety rules were extended with it, so data fetched from the user's machine is treated as private. None of it applies unless the process environment sets the variable. Hook and plugin forwarding over the remote-control channel no longer follows the old variables.\n\n- Area: Remote Tools\n- Names: `CLAUDE_CODE_REMOTE_TOOLS_FORWARD`\n- Tier: Use it now\n- Useful: 5\/5\n- Signal: 5\/5"}