{"version":"2.1.288","anchor":"new-guard-prompts-on-rm-hidden-inside-sh-c-scripts-wit","canonical_anchor":"new-env-var-claude-code-disable-inline-shell-rm-prompt","heading":"Bash permission check now catches risky rm inside sh -c scripts","tier":"use","area":"Permissions","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288\/e\/new-guard-prompts-on-rm-hidden-inside-sh-c-scripts-wit","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288","markdown":"### Bash permission check now catches risky rm inside sh -c scripts\n\nAn `rm` hidden in a `bash -c` script with a run-time target now needs explicit approval, with `CLAUDE_CODE_DISABLE_INLINE_SHELL_RM_PROMPT` to turn it off\n\n**Unclear.** Whether the check is active by default depends on an additional condition that was not traced.\n\n**What**\n\nBefore Claude runs a shell command, Claude Code checks whether it needs your permission. That check now looks inside inline shell scripts, meaning code passed as text to `bash -c`, `sh -c` or `zsh -c`, and judges any `rm` in them.\n\n- An `rm` whose target comes from a variable or from another command's output, so it is only known when the script runs, now triggers a prompt: `Dangerous rm operation in a shell -c script`.\n\n- A script that cannot be checked, or a permission-rule deny found inside the script, also leads to a prompt instead of automatic approval.\n\n- The prompt counts as a dangerous-removal safety check (`dangerousRemoval` `safetyCheck`), so your permission rules cannot allow it automatically.\n\n- Nested shell code is judged recursively, with a shared depth and budget limit. The result of this new pass is `inlineShellScript`.\n\n- `CLAUDE_CODE_DISABLE_INLINE_SHELL_RM_PROMPT` turns the check off. It is listed beside the existing `CLAUDE_CODE_DISABLE_SUBSTITUTION_RM_PROMPT` and `CLAUDE_CODE_DISABLE_DANGEROUS_RM_TIMEOUT`. The check also does nothing unless a further internal condition passes, and that condition was not traced.\n\n- A new `heredoc_redirect` path re-reads commands with plain unquoted heredocs (blocks of text fed into a command) so they can be auto-allowed when sandboxing is on and auto-allow for sandboxed commands is enabled. It is behind `tengu_amber_larch`. The flag server returned on for this site's account and for the anonymous baseline, but no reading has been taken under this release yet.\n\n**Why**\n\nBefore this change, an `rm` wrapped inside a `bash -c` script could get past the dangerous-removal check that a plain `rm` would hit. Expect new prompts for scripted commands such as `rm -rf $VAR`, and know that allow rules will not silence them. Set the environment variable if you need the old behaviour.\n\n- Area: Permissions\n- Names: `CLAUDE_CODE_DISABLE_INLINE_SHELL_RM_PROMPT`\n- Tier: Use it now\n- Useful: 4\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: yes"}