What
Before Claude runs a shell command, Claude Code checks whether it needs your permission. That check now looks inside inline shell scripts, meaning code passed as text to bash -c, sh -c or zsh -c, and judges any rm in them.
- An
rmwhose target comes from a variable or from another command's output, so it is only known when the script runs, now triggers a prompt:Dangerous rm operation in a shell -c script. - A script that cannot be checked, or a permission-rule deny found inside the script, also leads to a prompt instead of automatic approval.
- The prompt counts as a dangerous-removal safety check (
dangerousRemovalsafetyCheck), so your permission rules cannot allow it automatically. - Nested shell code is judged recursively, with a shared depth and budget limit. The result of this new pass is
inlineShellScript. CLAUDE_CODE_DISABLE_INLINE_SHELL_RM_PROMPTturns the check off. It is listed beside the existingCLAUDE_CODE_DISABLE_SUBSTITUTION_RM_PROMPTandCLAUDE_CODE_DISABLE_DANGEROUS_RM_TIMEOUT. The check also does nothing unless a further internal condition passes, and that condition was not traced.- A new
heredoc_redirectpath re-reads commands with plain unquoted heredocs (blocks of text fed into a command) so they can be auto-allowed when sandboxing is on and auto-allow for sandboxed commands is enabled. It is behindtengu_amber_larch. The flag server returned on for this site's account and for the anonymous baseline, but no reading has been taken under this release yet.
Why
Before this change, an rm wrapped inside a bash -c script could get past the dangerous-removal check that a plain rm would hit. Expect new prompts for scripted commands such as rm -rf $VAR, and know that allow rules will not silence them. Set the environment variable if you need the old behaviour.
Names in the bundleCLAUDE_CODE_DISABLE_INLINE_SHELL_RM_PROMPT
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
The check also depends on a further condition that is not resolved, so whether it is active by default is not established.
Anthropic's release notes agree
Fixed a dangerous rm (such as one on / or the home directory) inside a bash -c or sh -c script running without a prompt in bypassPermissions…
The name it cites is new in this build
New in this build: CLAUDE_CODE_DISABLE_INLINE_SHELL_RM_PROMPT