{"version":"2.1.289","anchor":"find-rm-no-longer-auto-allowed-in-the-read-only-find-patter","canonical_anchor":"find-rm-no-longer-auto-allowed-in-the-read-only-find-patter","heading":"find -rm is no longer auto-approved as a read-only command","tier":"notice","area":"Permissions","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.289\/e\/find-rm-no-longer-auto-allowed-in-the-read-only-find-patter","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.289","markdown":"### find -rm is no longer auto-approved as a read-only command\n\nClaude Code now treats `find ... -rm` like `find ... -delete`: it is not auto-allowed as read-only and is flagged as destructive\n\n**Unclear.** It is not clear whether the server-side setting affects the read-only pattern itself, which has `-rm` built in, or only the separate list of blocked options.\n\n**What**\n\nClaude Code automatically allows some shell commands without asking you first, because they only read files. A `find` command (which searches for files) was on that list unless it used an action such as `-delete` or `-exec`. The `-rm` action has now been added to the blocked actions.\n\n- Read-only check: the auto-allow pattern for `find` and the set of blocked `find` actions both now include `-rm`. The pattern now reads `-delete\\b|-rm\\b|-exec\\b|-execdir\\b|-ok\\b|-okdir\\b|-fprint0?\\b|-fls\\b|-fprintf\\b|-files0-from\\b`, so a `find` using `-rm` is no longer treated as safe.\n\n- Spacing: the pattern now accepts only spaces and tabs between arguments (`[ \\t]+` instead of `\\s`), so a line break can no longer separate `find` arguments.\n\n- Destructive-command list: the pattern that marks commands as destructive used to match only `find ... -delete`. It now matches `find ... -rm` too, so those commands get the same handling as `-delete`.\n\n- Remote switch: the `-rm` check sits behind a small helper, called from the bash read-only check and from one other place. It treats `-rm` as blocked unless the remote flag `tengu_warm_sunrise` has been explicitly set to false by a server. Nothing has been read about the state of this flag.\n\n**Why**\n\nBefore, a `find ... -rm` command could match the read-only pattern and run without a permission prompt. It now goes through the normal permission check, and a server-side flag exists that could undo this.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: yes"}