{"version":"2.1.290","anchor":"auto-mode-permission-tool-check-hardening-and-new-decision","canonical_anchor":"auto-mode-permission-tool-check-hardening-and-new-decision","heading":"Auto mode offers fewer always-allow rules, and git and rsync parsing changes behind a gate","tier":"notice","area":"Auto Mode","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/auto-mode-permission-tool-check-hardening-and-new-decision","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Auto mode offers fewer always-allow rules, and git and rsync parsing changes behind a gate\n\nAuto mode stops offering permanent allow rules in more cases, and a new gate changes how git and rsync options are read in safety checks\n\n**Unclear.** What the remote switch's built-in default is, and what the new `git` option path does, are not clear.\n\n**What**\n\nIn auto mode, Claude Code decides permissions without asking, using a safety classifier, a model that judges whether a tool call is safe. When the classifier denies something, Claude Code may suggest a rule to always allow it. That suggestion is now held back in more cases:\n\n- when a hook made the decision (hooks are your own commands that run at set points)\n\n- when the call runs remotely\n\n- when the check covers computer-use tools or MCP tools (tools added by outside programs)\n\nThe record of each auto-mode decision also gains an `mcpRemoteSessionAllowOverride` field.\n\nBehind a new gate, `tengu_golden_panda`, the command safety check reads some commands differently:\n\n- For git, values given with `-c` or `-C`, and other options that are only known when the command runs, are now flagged as worked out at run time instead of treated as plain values. What uses that flag was not traced.\n\n- The pattern for `rsync -e` has a second version.\n\nThe gate is read with a safe fallback. Nothing has been read about it.\n\n**Why**\n\nYou will be offered permanent allow rules less often in cases where such a rule would be unsafe or not apply. The git and rsync changes can affect which commands are flagged in permission checks.\n\n- Area: Auto Mode\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: no"}