{"version":"2.1.286","anchor":"served-tool-permission-second-check-changes-tengu-violin","canonical_anchor":"served-tool-permission-second-check-changes-tengu-violin","heading":"Permission checks for tools run remotely get retries and stricter shell handling","tier":"soon","area":"Auto Mode","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286\/e\/served-tool-permission-second-check-changes-tengu-violin","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286","markdown":"### Permission checks for tools run remotely get retries and stricter shell handling\n\nRemote tool permission checks can retry a timed-out safety check and treat unreadable shell commands as needing a person, behind three switches\n\n**Unclear.** What each of the three switches controls on its own, and exactly how the settings file exception works, is not clear.\n\n**What**\n\nWhen Claude Code runs tools on a remote service, each action goes through a permission check. In auto mode that can include a second check by a safety classifier (a model that judges whether an action is safe to approve). Three changes are behind remote switches that default to off:\n\n- a second check that timed out is retried, where before it ran only once\n\n- Claude Code's own check can run ahead of time alongside a hold on the action\n\n- shell commands that cannot be read clearly are treated as needing a person to approve them, with an exception that involves the settings file\n\nThe flag server returned on for this site's account and for the anonymous baseline on all three switches. No reading has been taken under this release yet.\n\n**Why**\n\nThis tunes how actions are approved automatically in cloud sessions. The shell change means an unclear command waits for you instead of being approved without you.\n\n- Flag `tengu_violin_tailgut`: Off by default, switched on for this account (read for one account on one subscription tier against v2.1.286; this account: on, anonymous baseline: on, compiled default: off) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Flag `tengu_violin_hair`: Off by default, switched on for this account (read for one account on one subscription tier against v2.1.286; this account: on, anonymous baseline: on, compiled default: off) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Flag `tengu_violin_ferrule`: Off by default, switched on for this account (read for one account on one subscription tier against v2.1.286; this account: on, anonymous baseline: on, compiled default: off) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: Auto Mode\n- Tier: Nothing to try yet\n- Useful: 3\/5\n- Signal: 4\/5\n- Present in the build but not switched on"}