{"version":"2.1.287","anchor":"safety-check-path-decisions-gain-an-uncertain-outcome","canonical_anchor":"safety-check-path-decisions-gain-an-uncertain-outcome","heading":"Path-write safety checks gain 'uncertain' and internal hard-deny outcomes","tier":"internal","area":"Permissions","scope":null,"heads_up":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.287\/e\/safety-check-path-decisions-gain-an-uncertain-outcome","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.287","markdown":"### Path-write safety checks gain 'uncertain' and internal hard-deny outcomes\n\nThe safety check on file-path writes can now return 'settings' or 'uncertain', keeps hard denies, and adds an internalHardDeny class auto-approval can't override\n\n**Unclear.** It is not clear which kinds of path give the uncertain result.\n\n**What**\n\nA safety check is a point where Claude Code stops before writing to a file path it considers risky. This release changes how that check reaches its verdict:\n\n- `settings` and `uncertain` outcomes: one kind of `safetyCheck` reason now classifies the write as \"settings\", a second kind returns \"uncertain\", and a `safetyCheck` on a `blockedPath` is handled differently. Before, the result was only \"settings\" or \"none\".\n\n- Denials kept: when the path check hits a deny, it no longer stops there and returns that deny's reason. It keeps the deny, combines it with the safety-check message, and adds an `also` list that can include `internalHardDeny`.\n\n- No automatic approval: the classifier, the part of auto mode that approves actions without asking you, can no longer approve these cases.\n\n- New `internalHardDeny` permission class: the table of permission reasons gains a `servedUnplaceable` field. It is true only on `internalHardDeny` and false on every other class. Where `internalHardDeny` is actually assigned as a reason was not found, and the code that reads it was not confirmed.\n\n**Why**\n\nThis changes when a path-write safety check defers to you and when it defers to your settings. If you use auto mode, you may see different wording when a write is denied, and some of these denials can no longer be approved automatically.\n\n- Area: Permissions\n- Tier: Under the hood\n- Useful: 2\/5\n- Signal: 3\/5"}