What probably matters to youSection of the release
What
Before Claude runs a shell command, Claude Code checks whether it needs your permission. That check now looks inside inline shell scripts, meaning code passed as text to bash -c, sh -c or zsh -c, and judges any rm in them.
An rm whose target comes from a variable or from another command's output, so it is only known when the script runs, now triggers a prompt: Dangerous rm operation in a shell -c script.
A script that cannot be checked, or a permission-rule deny found inside the script, also leads to a prompt instead of automatic approval.
The prompt counts as a dangerous-removal safety check (dangerousRemovalsafetyCheck), so your permission rules cannot allow it automatically.
Nested shell code is judged recursively, with a shared depth and budget limit. The result of this new pass is inlineShellScript.
A new heredoc_redirect path re-reads commands with plain unquoted heredocs (blocks of text fed into a command) so they can be auto-allowed when sandboxing is on and auto-allow for sandboxed commands is enabled. It is behind tengu_amber_larch. The flag server returned on for this site's account and for the anonymous baseline, but no reading has been taken under this release yet.
Why
Before this change, an rm wrapped inside a bash -c script could get past the dangerous-removal check that a plain rm would hit. Expect new prompts for scripted commands such as rm -rf $VAR, and know that allow rules will not silence them. Set the environment variable if you need the old behaviour.