Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.290 ·

Cloud sessions can delete files they created themselves without asking

Remote tool serving gains an own-made delete check so an rm of files the session itself just created can skip the prompt, plus a new trust message

Group of 3 You'll notice Improvements
JSON All of v2.1.290
You'll noticeTier: how much it should matter to you
3Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.290,
ImprovementsSection of the release

Unclear What switches this on, and whether it applies outside remote sessions, is unclear.

What

Claude Code can let a cloud session use tools on your own computer. This is called remote tool serving. A new check, ownMadeDelete, lets such a session remove files and folders it created itself without asking you first. The session keeps a record of what it made with mkdir, touch or the Write tool, the tool Claude uses to create files. A later delete can go ahead only if Claude Code can prove the delete touches nothing else.

  • Only a single rm command qualifies, and only with the flags -r, -f, -d and -v.
  • Every target must be on the session's record and unchanged since it was created. The removal runs through a folder that was held open in advance, so the folder cannot be swapped out in the meantime.
  • The check declines in a sandbox (a walled-off area that limits what commands can touch), when owner rules apply, when the session is busy, on Windows, for masked paths, and in other cases.
  • Several new refusal messages explain a decline. One says the files could not be checked again just before removal, so nothing was removed, and asks for the command to be sent again.
  • In permission handling, a delete that would otherwise be blocked can be let through when ownMadeDelete is on and the check agrees. An approved delete is then recorded.
  • The own_record unattended setting now gives a "consent" answer. Unattended means nobody is present to answer permission prompts.
  • Permission prompts gain new text, ask.settings_person_only, for shell commands whose writes could not be worked out. A shell command is a command typed into a terminal.
  • Two new internal names, mcpPathWhy and serverAskUnderPlanFloor, were added. What they do was not traced.
  • The not_marked repository-trust refusal changed. It used to tell Claude to start a new session or use one with nothing attached. It now tells Claude to call a trust tool once and put the question to you.

The serving path sits behind tengu_remote_tool_serve. Nothing has been read about that gate.

Why

A cloud session that cleans up its own scratch files no longer needs to stop and ask each time. The proof is narrow, so files the session did not make, or that changed after it made them, still go through the normal permission checks. A trust refusal now leads to one question for you instead of telling Claude to start over.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhat switches this on, and whether it applies outside remote sessions, is unclear.

See this entry in the whole of v2.1.290 →

Feedback