You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
Auto ModeArea: what it touches
ImprovementsKind: in v2.1.290,
ImprovementsSection of the release
Unclear What the remote switch's built-in default is, and what the new git option path does, are not clear.
What
In auto mode, Claude Code decides permissions without asking, using a safety classifier, a model that judges whether a tool call is safe. When the classifier denies something, Claude Code may suggest a rule to always allow it. That suggestion is now held back in more cases:
when a hook made the decision (hooks are your own commands that run at set points)
when the call runs remotely
when the check covers computer-use tools or MCP tools (tools added by outside programs)
The record of each auto-mode decision also gains an mcpRemoteSessionAllowOverride field.
Behind a new gate, tengu_golden_panda, the command safety check reads some commands differently:
For git, values given with -c or -C, and other options that are only known when the command runs, are now flagged as worked out at run time instead of treated as plain values. What uses that flag was not traced.
The pattern for rsync -e has a second version.
The gate is read with a safe fallback. Nothing has been read about it.
Why
You will be offered permanent allow rules less often in cases where such a rule would be unsafe or not apply. The git and rsync changes can affect which commands are flagged in permission checks.
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhat the remote switch's built-in default is, and what the new `git` option path does, are not clear.