When you start a cloud session (a Claude Code session that runs on a remote machine instead of your own), Claude Code can send along settings from your home folder. It now checks that material for text that looks like a credential, meaning a password, API key, token or similar secret. It checks two kinds of material:
- Permission rules: the allow, ask and deny rules that decide what Claude may do. A rule that looks like it contains a credential is withheld.
- Memory and instruction files such as CLAUDE.md, including any files they import. A file that looks like it contains a credential is left behind, and Claude Code notes the line number where the match was found.
The count of what was and was not forwarded now includes how many pieces of text were withheld for this reason. Before, permission rules were only checked for problems such as being invalid or too large, with no check for credentials.
It lowers the chance of a secret in your local settings or instruction files being copied to a remote machine. If a rule or file you rely on is missing in a cloud session, a credential-like string inside it may be the reason.