Unclear Which part of this the tengu_ticklish_pnueli flag controls is not clear.
Claude Code keeps a list of sensitive credential files that it blocks access to. That list now covers more locations:
- Windows profile credential files reached from WSL (Windows Subsystem for Linux) through
/mntpaths. - The same files reached through Windows short file names, the old 8.3-style names such as
PROGRA~1.
The sandbox, which limits what commands Claude runs can touch, now also handles read rules that point outside the project folder and rules it cannot decide either way. This build also reads a server flag, tengu_ticklish_pnueli, which is off unless it is switched on remotely. The flag server has returned it on for this site's account.
On WSL and Windows the same credential file can be reached under more than one path. Blocking those extra paths makes it harder to read the file by going around the usual name.
tengu_ticklish_pnueli Off by default, switched on for this accountThe shipped code defaults this off, and the flag server returned on for the one account this site reads on this version. That is the reading that makes the entry above worth a second look, and it still says nothing about your account.
This account: on · anonymous baseline: on · compiled default in v2.1.290: off
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.290. It isn't a statement about your account. What a flag value here can and cannot tell you
Which part of this the `tengu_ticklish_pnueli` flag controls is not clear.
New in this build: tengu_ticklish_pnueli