Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.288 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.288 ·

Bash permission check now catches risky rm inside sh -c scripts

An rm hidden in a bash -c script with a run-time target now needs explicit approval, with CLAUDE_CODE_DISABLE_INLINE_SHELL_RM_PROMPT to turn it off

Group of 6 Use it now Improvements
JSON All of v2.1.288
Use it nowTier: how much it should matter to you
4Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
Bash ToolArea: what it touches
ImprovementsKind: in v2.1.288,
What probably matters to youSection of the release

What

Before Claude runs a shell command, Claude Code checks whether it needs your permission. That check now looks inside inline shell scripts, meaning code passed as text to bash -c, sh -c or zsh -c, and judges any rm in them.

  • An rm whose target comes from a variable or from another command's output, so it is only known when the script runs, now triggers a prompt: Dangerous rm operation in a shell -c script.
  • A script that cannot be checked, or a permission-rule deny found inside the script, also leads to a prompt instead of automatic approval.
  • The prompt counts as a dangerous-removal safety check (dangerousRemoval safetyCheck), so your permission rules cannot allow it automatically.
  • Nested shell code is judged recursively, with a shared depth and budget limit. The result of this new pass is inlineShellScript.
  • CLAUDE_CODE_DISABLE_INLINE_SHELL_RM_PROMPT turns the check off. It is listed beside the existing CLAUDE_CODE_DISABLE_SUBSTITUTION_RM_PROMPT and CLAUDE_CODE_DISABLE_DANGEROUS_RM_TIMEOUT. The check also does nothing unless a further internal condition passes, and that condition was not traced.
  • A new heredoc_redirect path re-reads commands with plain unquoted heredocs (blocks of text fed into a command) so they can be auto-allowed when sandboxing is on and auto-allow for sandboxed commands is enabled. It is behind tengu_amber_larch. The flag server returned on for this site's account and for the anonymous baseline, but no reading has been taken under this release yet.

Why

Before this change, an rm wrapped inside a bash -c script could get past the dangerous-removal check that a plain rm would hit. Expect new prompts for scripted commands such as rm -rf $VAR, and know that allow rules will not silence them. Set the environment variable if you need the old behaviour.

Read from
Feature flag
tengu_amber_larch On for this account, and not off by default

The flag server returned on for the one account this site reads, and nothing in this release compiles it off by default. The compiled default is shown below, and says which it is when we cannot read one: a fifth of gates compile in a string or a number rather than on or off, and most published releases have no gate table behind them at all. No client can see what the server returns for your account.

This account: on · anonymous baseline: on · compiled default in v2.1.288: on

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

tengu_iridescent_boot Not enough to say

Nothing here resolved what this flag was doing on this version, so nothing here should be read as on or off.

This account: no value returned · anonymous baseline: no value returned · compiled default in v2.1.288: on

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

Read once, for one account on one subscription tier, against v2.1.288. It isn't a statement about your account. What a flag value here can and cannot tell you

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is unclear exactly how the inline script is judged.
The name it cites is new in this buildNew in this build: tengu_amber_larch

See this entry in the whole of v2.1.288 →

Feedback