Unclear What switches this on, and whether it applies outside remote sessions, is unclear.
What
Claude Code can let a cloud session use tools on your own computer. This is called remote tool serving. A new check, ownMadeDelete, lets such a session remove files and folders it created itself without asking you first. The session keeps a record of what it made with mkdir, touch or the Write tool, the tool Claude uses to create files. A later delete can go ahead only if Claude Code can prove the delete touches nothing else.
- Only a single
rmcommand qualifies, and only with the flags-r,-f,-dand-v. - Every target must be on the session's record and unchanged since it was created. The removal runs through a folder that was held open in advance, so the folder cannot be swapped out in the meantime.
- The check declines in a sandbox (a walled-off area that limits what commands can touch), when owner rules apply, when the session is busy, on Windows, for masked paths, and in other cases.
- Several new refusal messages explain a decline. One says the files could not be checked again just before removal, so nothing was removed, and asks for the command to be sent again.
- In permission handling, a delete that would otherwise be blocked can be let through when
ownMadeDeleteis on and the check agrees. An approved delete is then recorded. - The
own_recordunattended setting now gives a "consent" answer. Unattended means nobody is present to answer permission prompts. - Permission prompts gain new text,
ask.settings_person_only, for shell commands whose writes could not be worked out. A shell command is a command typed into a terminal. - Two new internal names,
mcpPathWhyandserverAskUnderPlanFloor, were added. What they do was not traced. - The
not_markedrepository-trust refusal changed. It used to tell Claude to start a new session or use one with nothing attached. It now tells Claude to call a trust tool once and put the question to you.
The serving path sits behind tengu_remote_tool_serve. Nothing has been read about that gate.
Why
A cloud session that cleans up its own scratch files no longer needs to stop and ask each time. The proof is narrow, so files the session did not make, or that changed after it made them, still go through the normal permission checks. A trust refusal now leads to one question for you instead of telling Claude to start over.
What switches this on, and whether it applies outside remote sessions, is unclear.