Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.290 ·

Better detection of scripts passed directly to shells, including PowerShell

Claude Code recognises more ways of handing a shell an inline script, including PowerShell options like -EncodedCommand, in any capitalisation

You'll notice Improvements
JSON All of v2.1.290
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.290,
ImprovementsSection of the release

Unclear Whether this check is used for permission decisions was not confirmed.

What

A shell such as bash can run a script written straight on its command line, as in bash -c. Claude Code checks whether a shell command is doing this, and that check is now stricter:

  • For pwsh (PowerShell), it matches -c, -command, -cwa, -commandwithargs, -e, -ec and -encodedcommand, in any mix of capital and small letters.
  • For other shells, it matches a group of short flags that includes c, or --command.

This replaces an older pattern check.

Why

This most likely affects how Claude Code's permission and safety checks read wrapper commands such as bash -c and pwsh -EncodedCommand, so a script hidden inside one of these is spotted more reliably.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhether this check is used for permission decisions was not confirmed.

See this entry in the whole of v2.1.290 →

Feedback