{"version":"2.1.290","anchor":"shell-c-flag-detection-is-stricter-and-handles-pwsh-variant","canonical_anchor":"shell-c-flag-detection-is-stricter-and-handles-pwsh-variant","heading":"Better detection of scripts passed directly to shells, including PowerShell","tier":"notice","area":"Permissions","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/shell-c-flag-detection-is-stricter-and-handles-pwsh-variant","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Better detection of scripts passed directly to shells, including PowerShell\n\nClaude Code recognises more ways of handing a shell an inline script, including PowerShell options like `-EncodedCommand`, in any capitalisation\n\n**Unclear.** Whether this check is used for permission decisions was not confirmed.\n\n**What**\n\nA shell such as bash can run a script written straight on its command line, as in `bash -c`. Claude Code checks whether a shell command is doing this, and that check is now stricter:\n\n- For `pwsh` (PowerShell), it matches `-c`, `-command`, `-cwa`, `-commandwithargs`, `-e`, `-ec` and `-encodedcommand`, in any mix of capital and small letters.\n\n- For other shells, it matches a group of short flags that includes `c`, or `--command`.\n\nThis replaces an older pattern check.\n\n**Why**\n\nThis most likely affects how Claude Code's permission and safety checks read wrapper commands such as `bash -c` and `pwsh -EncodedCommand`, so a script hidden inside one of these is spotted more reliably.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: yes"}