What
Claude Code can run some shell commands without asking you first when it judges them read-only, or when a permission rule such as Bash(find:*) allows them. The checks behind that are stricter now, and these cases now ask for permission:
findoptions that different versions offindread differentlyfind,test,jobsorsetarguments that contain redirect characters or end in a backslash- Wildcard characters in a
findname-style argument, unless the pattern is quoted testarguments containing$, which are checked more strictly
find options that run commands or change files still cannot be allowed automatically by a Bash(find:*) rule.
Why
These close ways a find command could hide an action that runs something or changes files behind a rule meant only to allow searching. Expect some find commands that used to run silently to ask for approval.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
Exactly which `find` options are treated as read differently by different versions is not stated.