What
Claude Code automatically allows some shell commands without asking you first, because they only read files. A find command (which searches for files) was on that list unless it used an action such as -delete or -exec. The -rm action has now been added to the blocked actions.
- Read-only check: the auto-allow pattern for
findand the set of blockedfindactions both now include-rm. The pattern now reads-delete\b|-rm\b|-exec\b|-execdir\b|-ok\b|-okdir\b|-fprint0?\b|-fls\b|-fprintf\b|-files0-from\b, so afindusing-rmis no longer treated as safe. - Spacing: the pattern now accepts only spaces and tabs between arguments (
[ \t]+instead of\s), so a line break can no longer separatefindarguments. - Destructive-command list: the pattern that marks commands as destructive used to match only
find ... -delete. It now matchesfind ... -rmtoo, so those commands get the same handling as-delete. - Remote switch: the
-rmcheck sits behind a small helper, called from the bash read-only check and from one other place. It treats-rmas blocked unless the remote flagtengu_warm_sunrisehas been explicitly set to false by a server. Nothing has been read about the state of this flag.
Why
Before, a find ... -rm command could match the read-only pattern and run without a permission prompt. It now goes through the normal permission check, and a server-side flag exists that could undo this.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
It is not clear whether the server-side setting affects the read-only pattern itself, which has `-rm` built in, or only the separate list of…