Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.287 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.287 ·

Auto mode re-checks tool calls a hook rewrote, and permission checks now track their phase and round

When a hook rewrites a tool call after the server reviewed it, the local auto-mode check now judges that call, and permission checks track phase and round

Group of 6 Under the hood Internal Changes
JSON All of v2.1.287
Under the hoodTier: how much it should matter to you
1Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
PermissionsArea: what it touches
Internal ChangesKind: in v2.1.287,
Internal ChangesSection of the release

What

Auto mode lets Claude Code decide on its own whether a tool call may run. A tool call is one action Claude takes, such as running a command or editing a file. The decision is made by a classifier, an automatic reviewer. A hook is a script you set up to run at certain points, and it can rewrite a tool call's input before the call runs. This release changes how the permission check behaves after such a rewrite:

  • Local classifier for rewritten calls: if a hook rewrote a call's input, or the input of a call before it, after the server's classifier had already reviewed the response, the classifier on your machine now judges that one call. Before, the server's verdict was used as it was, and the retry fell back to the local classifier only when the server had not been asked.
  • Handed-off calls: a server verdict of "not requested" for a single call that was handed off can now be accepted under some conditions.
  • Hook updatedInput: when a hook returns updatedInput, the permission re-check now runs through an extra wrapper instead of a direct call. On another path, permissionRound is reset to empty.
  • Re-entry wrapper: a new wrapper runs permission checks in a reentry phase and cleans up toolDecisions afterwards.
  • Classifier health check: a new helper counts the classifier as healthy only when it ran and reported none of unavailable, transcriptTooLong, refusedBySafeguard, failureMode or errorKind.
  • Phase and round: the information passed to tools now exposes permissionPhase and permissionRound, which say which stage and which round of permission checking a call is in.
  • Messages to other sessions: the permission result for sending to another session now passes on decisionReason. Before, it carried only proceed, input and asked.
  • Logging: permission records now note whether a call was handed off (fromTurnHandoff), the order of asks (askOrder), the tool host status (toolHostStatus) and details of the MCP server behind a tool.

Why

A hook can change what a tool call actually does. Having the local classifier judge the rewritten call means the call that runs is the one that was reviewed, not only the original. If you use hooks that rewrite tool input in auto mode, you may see different approve or block decisions on those calls.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear what the extra step does or how prompts change as a result.

See this entry in the whole of v2.1.287 →

Feedback