Unclear It is not clear which of these checks apply in every setup and which depend on a setting or remote switch.
Claude Code can run tools on behalf of a remote host, meaning another program that asks Claude Code to carry out actions and asks for your approval. The permission checks around those tool calls now handle several cases differently:
- A path that is too long is refused.
- An approval that arrives after its time has run out is used up and nothing runs. The message says: "nothing ran, and the approval is used up. Run the tool again if it is still needed." Before, a late approval left the request waiting as still pending.
- If the check against your permission rules crashes, the tool call is denied rather than allowed.
- Refusals involving credential files and settings files are now recorded.
- Edits to settings files made through these remotely hosted tools are refused.
This release also reads a new environment variable, CLAUDE_CODE_REMOTE_TOOLS_HOST_ALLOWS_UNATTENDED, and passes it through to the programs Claude Code starts.
These changes decide what happens when an approval expires or a check goes wrong. In each case the tool now does not run, so an approval cannot quietly hang around and a failed check does not let a call through. If a remotely hosted tool reports that its approval was used up, run the tool again.
It is not clear which of these checks apply in every setup and which depend on a setting or remote switch.