{"version":"2.1.293","anchor":"served-shell-line-read-only-check-no-longer-limited-to-named","canonical_anchor":"served-shell-line-read-only-check-no-longer-limited-to-named","heading":"Read-only check for served shell lines now covers every tool","tier":"internal","area":"Bash","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.293\/e\/served-shell-line-read-only-check-no-longer-limited-to-named","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.293","markdown":"### Read-only check for served shell lines now covers every tool\n\nEvery tool now goes through the read-only check for served shell lines, and a check that fails counts as not read-only\n\n**Unclear.** Whether this lets more tool calls run as read-only in practice is unclear.\n\n**What**\n\nClaude Code checks whether a served shell line is read-only, meaning it only looks at things and changes nothing. Before, the check returned not read-only unless the tool was one of two particular tools working on files. That restriction is gone, so every tool now goes through the check.\n\nIf the check fails with an error, Claude Code reports \"a served shell line's read-only check threw; the line counts as not read-only\" and treats the line as not read-only.\n\n**Why**\n\nThis could change which tool calls count as read-only.\n\n- Area: Bash\n- Tier: Under the hood\n- Useful: 2\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: no"}