What
A served call is a tool call that a cloud session asks your machine to run for it. When the check is on, Claude Code now inspects served Bash or PowerShell commands for writes to this machine's own Claude Code settings files, or the folder that holds them:
- It follows directory changes (
cd,pushd),envand other wrapper words, and commands nested inside-c. - A command that definitely writes a settings file is refused. Nothing is run, and the model is told to make the change with the Edit or Write tool instead, so the change is held for the machine owner to review.
- If Claude Code cannot work out everything the command writes, the call is sent to a person for approval (reason
remote_call_unresolved_shell_write_ask). - Separately, an approval request raised by a settings-file safety check can no longer be approved automatically by the auto-mode classifier, the model that decides on permission requests in auto mode.
Both parts are controlled by the server flag tengu_violin_purfling, read in two places with different defaults. With no value from the server, the shell-write hold is off and the classifier exclusion is on. The classifier exclusion is lifted only if the server explicitly sends false. For this site's account and for an anonymous check, the flag server returned on, but no reading has been taken under this release yet.
Why
Without this, a remote session could use a shell command to rewrite the settings that decide its own permissions on your machine. Such changes now go through the tools the owner reviews, or to a person, instead of happening quietly.
tengu_violin_purfling On for this account, and not off by defaultThe flag server returned on for the one account this site reads, and nothing in this release compiles it off by default. The compiled default is shown below, and says which it is when we cannot read one: a fifth of gates compile in a string or a number rather than on or off, and most published releases have no gate table behind them at all. No client can see what the server returns for your account.
This account: on · anonymous baseline: on · compiled default in v2.1.283: not a boolean we can read
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.283. It isn't a statement about your account. What a flag value here can and cannot tell you
New in this build: tengu_violin_purfling