{"version":"2.1.287","anchor":"server-classifier-skipped-when-the-input-was-rewritten","canonical_anchor":"server-classifier-skipped-when-the-input-was-rewritten","heading":"Server safety verdicts are not reused after a tool's input is rewritten","tier":"internal","area":"Auto Mode","scope":null,"heads_up":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.287\/e\/server-classifier-skipped-when-the-input-was-rewritten","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.287","markdown":"### Server safety verdicts are not reused after a tool's input is rewritten\n\nIf a tool's input was rewritten, Claude Code no longer uses the server's classifier verdict for it\n\n**Unclear.** It is not clear what rewrites a tool's input.\n\n**What**\n\nBefore Claude Code runs a tool (an action such as editing a file or running a command), a classifier, an automatic check, can judge whether the action is safe to allow. Some of those judgments come from the server. If the tool's input has been rewritten, Claude Code now skips the server's judgment entirely and records the reason as `server_input_rewritten`.\n\n**Why**\n\nA judgment made about the original input does not apply to a changed one, so this stops an old verdict from approving an action it never saw.\n\n- Area: Auto Mode\n- Tier: Under the hood\n- Useful: 1\/5\n- Signal: 3\/5"}