What
Remote tools let a Claude Code cloud session run commands on your own computer. This release changes how such commands are approved and how project hooks run. A hook is a command your project sets up to run automatically at certain points.
- Project hooks can run inside a bubblewrap (
bwrap) sandbox, a walled-off area that limits what a program can see or do. It cuts the hook off from the network and other processes, gives read-only access to system folders, hides home folders, and applies extra limits through/run/claude-hook/apply-seccomp. - The sandbox is tried once first. If it cannot be used, Claude Code logs "[remote-tools] a project hook cannot be run in a sandbox on this machine" with a reason such as
bubblewrap_too_old(version 0.10.0 or later needed),no_bubblewrap,no_seccomp_stage,bubblewrap_failed,home_in_vieworcredentials_in_view. - On Linux this requires the server-controlled switch
tengu_violin_heelto be true, not set as a local override, plus a further check. macOS does not use that switch. A second switch,tengu_violin_saddle, guards the path used when sandboxing or a proxy is active. - New messages explain why auto mode (Claude acting without asking each time) is off for unattended commands from cloud sessions: consent not given, declined or unreadable; turned off by
remoteTools.allowUnattendedServingordisableAutoMode; or a built-in safety cut-off. - When a hook rewrites the input of a request that asked for approval, the rewrite is now classed as none,
own_hooks_aloneor unvouched. The message says the classifier answer was set aside only for unvouched rewrites. Before, it always said both the earlier answer and the classifier were set aside.
Why
You now see why a cloud session is asking for approval on your machine. The most recent reading of tengu_violin_heel, taken before this release, was on for this site's account and the anonymous baseline. If the sandbox is in use, a Linux project hook that needs the network may fail.
tengu_violin_heel Off by default, switched on for this accountThe shipped code defaults this off, and the flag server returned on for the one account this site reads on this version. That is the reading that makes the entry above worth a second look, and it still says nothing about your account.
This account: on · anonymous baseline: on · compiled default in v2.1.286: off
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
tengu_violin_saddle Off by default, switched on for this accountThe shipped code defaults this off, and the flag server returned on for the one account this site reads on this version. That is the reading that makes the entry above worth a second look, and it still says nothing about your account.
This account: on · anonymous baseline: on · compiled default in v2.1.286: off
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.286. It isn't a statement about your account. What a flag value here can and cannot tell you
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
In an unprivileged container, [bubblewrap](#os-level-enforcement) can't mount a fresh `/proc` filesystem, so sandboxed commands fail with a `bwrap` error such as `Can't mount proc on /newroot/proc: Operation not permitted`. Set [`enableWea…sandboxing see the edit
What the further check requires, and exactly which hook runs take the Linux sandbox path.
Anthropic's documentation has since written up bwrap, on Configure the sandboxed Bash tool.