What
Auto mode lets Claude Code decide on its own whether a tool call may run. A tool call is one action Claude takes, such as running a command or editing a file. The decision is made by a classifier, an automatic reviewer. A hook is a script you set up to run at certain points, and it can rewrite a tool call's input before the call runs. This release changes how the permission check behaves after such a rewrite:
- Local classifier for rewritten calls: if a hook rewrote a call's input, or the input of a call before it, after the server's classifier had already reviewed the response, the classifier on your machine now judges that one call. Before, the server's verdict was used as it was, and the retry fell back to the local classifier only when the server had not been asked.
- Handed-off calls: a server verdict of "not requested" for a single call that was handed off can now be accepted under some conditions.
- Hook
updatedInput: when a hook returnsupdatedInput, the permission re-check now runs through an extra wrapper instead of a direct call. On another path,permissionRoundis reset to empty. - Re-entry wrapper: a new wrapper runs permission checks in a
reentryphase and cleans uptoolDecisionsafterwards. - Classifier health check: a new helper counts the classifier as healthy only when it ran and reported none of
unavailable,transcriptTooLong,refusedBySafeguard,failureModeorerrorKind. - Phase and round: the information passed to tools now exposes
permissionPhaseandpermissionRound, which say which stage and which round of permission checking a call is in. - Messages to other sessions: the permission result for sending to another session now passes on
decisionReason. Before, it carried onlyproceed,inputandasked. - Logging: permission records now note whether a call was handed off (
fromTurnHandoff), the order of asks (askOrder), the tool host status (toolHostStatus) and details of the MCP server behind a tool.
Why
A hook can change what a tool call actually does. Having the local classifier judge the rewritten call means the call that runs is the one that was reviewed, not only the original. If you use hooks that rewrite tool input in auto mode, you may see different approve or block decisions on those calls.
It is not clear what the extra step does or how prompts change as a result.