Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.53 Home All releases olderv2.1.52 v2.1.54newer
Claude Code v2.1.53

Bash Command Security Checks: Unicode Whitespace and Mid-Word Hash

What

Two new security checks detect potentially dangerous command patterns before execution.

Details
  • Unicode whitespace detection: Commands containing exotic Unicode whitespace characters (such as non-breaking spaces \u00A0, em spaces \u2000-\u200A, and others) are now flagged, as these can cause parsing inconsistencies between shell-quote and bash
  • Mid-word hash detection: Commands containing # characters mid-word (e.g., not preceded by whitespace) are flagged because shell-quote and bash parse these differently — bash treats # as a comment start in some contexts while shell-quote does not
  • Both checks trigger a user confirmation prompt ("ask" behavior) rather than blocking outright
Evidence

New security check IDs UNICODE_WHITESPACE and MID_WORD_HASH (search for "UNICODE_WHITESPACE" and "MID_WORD_HASH")

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

See this entry in the whole of v2.1.53 →