{"version":"2.1.290","anchor":"shell-command-classifier-returns-certainpossiblenone","canonical_anchor":"shell-command-classifier-returns-certainpossiblenone","heading":"A shell command check now answers certain, possible or none","tier":"internal","area":"Permissions","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/shell-command-classifier-returns-certainpossiblenone","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### A shell command check now answers certain, possible or none\n\nA check on shell commands that run commands held in variables now gives three answers, with possible when it cannot work everything out\n\n**Unclear.** What this check decides beyond permission handling is not clear.\n\n**What**\n\nClaude Code checks whether a shell command hands the shell another command held in a variable or produced by another command. That check used to answer yes or no. It now gives one of three answers:\n\n- certain\n\n- possible, when not everything in the command could be worked out\n\n- none\n\nThe explanation shown with such a command is also shorter: it no longer ends with \", which this reading cannot follow\".\n\n**Why**\n\nCommands Claude Code cannot fully work out are now treated as a possible match rather than a no, which makes permission decisions more cautious.\n\n- Area: Permissions\n- Tier: Under the hood\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: no"}