Before Claude runs a shell command, Claude Code reads it to work out what it will do and whether it needs your permission. In a shell, a backslash at the end of a line joins it to the next line. That reader now follows such joins even when they fall in the middle of:
- operators such as
&& - redirections such as
<< - heredoc markers (a heredoc is a block of text passed to a command, ended by a chosen word)
- the openers
$(and${, which run or expand something inside a command
It also finds heredoc end words that are split across joined lines. The reader now marks a command as unreadable when it contains:
- a heredoc end word it cannot spell the way bash would
- a heredoc end word that reads as empty
- a
{that could either start a group of commands or be a plain argument - a
${...@P}expansion, which runs whatever the variable holds
Before, a line break in the middle of &&, <<, $( or ${ could make the reader see a different command from the one the shell runs, which could hide a command inside it from permission checks. Now, when the reader cannot follow a command, it says so instead of trusting its own reading.
What happens next with a command marked unreadable is not settled, though most likely Claude Code asks you for permission.