{"version":"2.1.283","anchor":"served-calls-blocked-from-reading-or-changing-credential-sto","canonical_anchor":"served-calls-blocked-from-reading-or-changing-credential-sto","heading":"Cloud sessions blocked from this machine's credential stores, keychains and personal credentials","tier":"notice","area":"Remote Tools","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283\/e\/served-calls-blocked-from-reading-or-changing-credential-sto","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283","markdown":"### Cloud sessions blocked from this machine's credential stores, keychains and personal credentials\n\nServed calls from cloud sessions are denied access to credential files, keychains and, under tengu_violin_lining, SSH keys and cloud logins\n\n**What**\n\nWhen a cloud session runs tools on your machine through remote tool execution (a served call), Claude Code now adds deny rules under the source `hostCredential`. They block reading or changing:\n\n- The connection's own credential, and the credential file named in `CLAUDE_CODE_HOST_CREDS_FILE`.\n\n- `\/proc\/*\/environ` on Linux, which exposes other programs' environment variables.\n\n- Keychain command-line tools: `security` on macOS and `secret-tool` on Linux.\n\n- On Windows, Credential Manager, SecretManagement, PasswordVault and `runas \/savecred`, detected in Bash and PowerShell commands.\n\nMCP tool inputs whose paths reach these locations are refused, or sent to you for approval when the path cannot be vouched for.\n\nWhen the server flag `tengu_violin_lining` is on, two more things apply:\n\n- Personal credentials are added (`personal_credential`), including `~\/.ssh`, `~\/.aws`, `~\/.config\/gcloud`, `~\/.azure`, `~\/.kube`, `~\/.gnupg`, `~\/.config\/gh`, `~\/.config\/glab-cli`, `~\/.netrc`, `~\/.git-credentials`, `~\/.npmrc`, `~\/.pypirc`, `~\/.pgpass` and more. A refused call gets a message naming the file.\n\n- `sandboxAutoAllowSuspended` is set for served calls, so sandboxed commands from a cloud session no longer skip the permission prompt.\n\nThe flag counts as on unless the server sends false without an override. That includes when no value arrives or reading it fails. For this site's account and for an anonymous check, the flag server returned on, but no reading has been taken under this release yet.\n\n**Why**\n\nThis keeps a cloud-driven agent from reading or changing your saved logins and keys, even for a command you would otherwise allow.\n\n- Flag `tengu_violin_lining`: On for this account, and not off by default (read for one account on one subscription tier against v2.1.283; this account: on, anonymous baseline: on, compiled default: on) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: Remote Tools\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 4\/5"}