Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.64 Home All releases olderv2.1.63 v2.1.66newer
Claude Code v2.1.64

Bash Command Security Checks

What

New security checks detect and flag potentially obfuscated bash commands that could bypass permission checks.

Details
  • Detects commands containing quoted newlines followed by #-prefixed lines, which can hide arguments from line-based permission scanning
  • Detects consecutive quote characters at word start (potential obfuscation)
  • Detects empty quote pairs adjacent to quoted dashes (flag obfuscation)
  • Sanitizes redirects to Windows NUL device by replacing with /dev/null
  • Flagged commands trigger an "ask" behavior requiring explicit user approval
Evidence

Security checks (search for "potential obfuscation", "quoted newline", "$1/dev/null")

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.64 →