{"version":"2.1.295","anchor":"bash-tool-read-only-command-check-now-reports-which-command","canonical_anchor":"bash-tool-read-only-command-check-now-reports-which-command","heading":"Bash permission checks now say which command was not read-only","tier":"internal","area":"Permissions","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295\/e\/bash-tool-read-only-command-check-now-reports-which-command","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295","markdown":"### Bash permission checks now say which command was not read-only\n\nWhen a shell command needs permission because it is not read-only, Claude Code now records which part of it caused that\n\n**What**\n\nBefore running a shell command, Claude Code checks whether it only reads things. Commands that do are allowed more freely, and others need further permission checks. When a command fails this check, the result now carries the text of the exact command that was not read-only, along with a reason.\n\nIn a session that runs shell commands only in its cloud environment, the reason says that no command can be verified as read-only there.\n\n**Why**\n\nThe permission prompt and the usage data can point at the exact part of a longer command that made Claude Code ask, not just say that it asked.\n\n- Area: Permissions\n- Tier: Under the hood\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: no"}