Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.288 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.288 ·

Bash permission check now catches risky rm inside sh -c scripts

An rm hidden in a bash -c script with a run-time target now needs explicit approval, with CLAUDE_CODE_DISABLE_INLINE_SHELL_RM_PROMPT to turn it off

Group of 6 Use it now No documentation found Improvements
JSON All of v2.1.288
Use it nowTier: how much it should matter to you
4Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.288,
What probably matters to youSection of the release

What

Before Claude runs a shell command, Claude Code checks whether it needs your permission. That check now looks inside inline shell scripts, meaning code passed as text to bash -c, sh -c or zsh -c, and judges any rm in them.

  • An rm whose target comes from a variable or from another command's output, so it is only known when the script runs, now triggers a prompt: Dangerous rm operation in a shell -c script.
  • A script that cannot be checked, or a permission-rule deny found inside the script, also leads to a prompt instead of automatic approval.
  • The prompt counts as a dangerous-removal safety check (dangerousRemoval safetyCheck), so your permission rules cannot allow it automatically.
  • Nested shell code is judged recursively, with a shared depth and budget limit. The result of this new pass is inlineShellScript.
  • CLAUDE_CODE_DISABLE_INLINE_SHELL_RM_PROMPT turns the check off. It is listed beside the existing CLAUDE_CODE_DISABLE_SUBSTITUTION_RM_PROMPT and CLAUDE_CODE_DISABLE_DANGEROUS_RM_TIMEOUT. The check also does nothing unless a further internal condition passes, and that condition was not traced.
  • A new heredoc_redirect path re-reads commands with plain unquoted heredocs (blocks of text fed into a command) so they can be auto-allowed when sandboxing is on and auto-allow for sandboxed commands is enabled. It is behind tengu_amber_larch. The flag server returned on for this site's account and for the anonymous baseline, but no reading has been taken under this release yet.

Why

Before this change, an rm wrapped inside a bash -c script could get past the dangerous-removal check that a plain rm would hit. Expect new prompts for scripted commands such as rm -rf $VAR, and know that allow rules will not silence them. Set the environment variable if you need the old behaviour.

Read from
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhether the check is active by default depends on an additional condition that was not traced.
Anthropic's release notes agreeFixed sandboxed heredocs with an unquoted delimiter (python3 <<EOF) asking for approval on every run under sandbox auto-allow when the body…
The name it cites is new in this buildNew in this build: CLAUDE_CODE_DISABLE_INLINE_SHELL_RM_PROMPT

See this entry in the whole of v2.1.288 →

Feedback