In auto mode, a separate model checks each action Claude wants to take and blocks the risky ones. That checker's instructions now come in two versions, the current "baseline" and a stricter "candidate". The candidate wording:
- extends existing limits to connected apps and accounts, such as mail, calendar, drive, transfers, trades, refunds and payouts
- blocks unrequested commits in a connected app and changes to accounts or standing rules
- adds rules on clicks done through page scripts, which tool call is being judged, secrets, restricted destinations, and copies keeping their sharing settings
Setting CLAUDE_CODE_AUTO_MODE_CANDIDATE_WORDING chooses the wording and takes priority. Otherwise the tengu_marble_finch gate decides, and without it Claude Code uses the baseline. If the candidate cannot be built cleanly, Claude Code logs a warning and uses the baseline.
With the candidate wording, auto mode blocks more actions in browser, desktop and connected-app sessions, so some actions it used to allow may now be stopped.
tengu_marble_finch Not enough to sayNothing here resolved what this flag was doing on this version, so nothing here should be read as on or off.
This account: no value returned · anonymous baseline: no value returned · compiled default in v2.1.284: off
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.284. It isn't a statement about your account. What a flag value here can and cannot tell you
New in this build: tengu_marble_finch