What
Claude Code's permission check decides whether a command runs straight away or asks you first. It gains two new reasons to ask:
settings_file_named: a shell command that is not read-only and names one of Claude Code's own settings or credential files is raised from allow to ask, with the message "This command names one of ...'s own Claude Code settings or credential files". This case is now recorded alongside the existing holds for the 'settings' and 'uncertain' verdicts.served_mcp_web_address: applies when a web address is given to one of a cloud session's own MCP tools, which are add-on tools the session provides. It also blocks the shortcut that would allow the command automatically from an allowlist.web_addressverdict: when scanning a shell command for file paths, a bare word that looks like a web address with no local path meaning now returns "web_address" instead of going through the protected-path check. Before, such a word could come back as ask or deny as if it touched a protected file. This scan change sits behind a feature check.
Why
Cloud and device sessions will ask before more commands that touch Claude Code's settings, while commands that only mention a web address are no longer treated as if they touched a protected path.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
It is not clear whether this check is switched on, as it depends on a condition that was not traced.