{"version":"2.1.283","anchor":"shell-commands-that-write-the-hosts-claude-code-settings-ar","canonical_anchor":"shell-commands-that-write-the-hosts-claude-code-settings-ar","heading":"Cloud sessions' shell commands that write this machine's Claude Code settings are held for the owner (tengu_violin_purfling)","tier":"notice","area":"Remote Tools","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283\/e\/shell-commands-that-write-the-hosts-claude-code-settings-ar","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283","markdown":"### Cloud sessions' shell commands that write this machine's Claude Code settings are held for the owner (tengu_violin_purfling)\n\nServed Bash\/PowerShell commands that write Claude Code settings files are denied or sent for approval, and auto mode cannot approve those asks\n\n**What**\n\nA served call is a tool call that a cloud session asks your machine to run for it. When the check is on, Claude Code now inspects served Bash or PowerShell commands for writes to this machine's own Claude Code settings files, or the folder that holds them:\n\n- It follows directory changes (`cd`, `pushd`), `env` and other wrapper words, and commands nested inside `-c`.\n\n- A command that definitely writes a settings file is refused. Nothing is run, and the model is told to make the change with the Edit or Write tool instead, so the change is held for the machine owner to review.\n\n- If Claude Code cannot work out everything the command writes, the call is sent to a person for approval (reason `remote_call_unresolved_shell_write_ask`).\n\n- Separately, an approval request raised by a settings-file safety check can no longer be approved automatically by the auto-mode classifier, the model that decides on permission requests in auto mode.\n\nBoth parts are controlled by the server flag `tengu_violin_purfling`, read in two places with different defaults. With no value from the server, the shell-write hold is off and the classifier exclusion is on. The classifier exclusion is lifted only if the server explicitly sends false. For this site's account and for an anonymous check, the flag server returned on, but no reading has been taken under this release yet.\n\n**Why**\n\nWithout this, a remote session could use a shell command to rewrite the settings that decide its own permissions on your machine. Such changes now go through the tools the owner reviews, or to a person, instead of happening quietly.\n\n- Flag `tengu_violin_purfling`: On for this account, and not off by default (read for one account on one subscription tier against v2.1.283; this account: on, anonymous baseline: on, compiled default: not a boolean we can read) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: Remote Tools\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 4\/5"}