Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.72 Home All releases olderv2.1.71 v2.1.73newer
Claude Code v2.1.72

Tree-Sitter Bash Security Analyzer Rewrite

The shell command security analyzer has been significantly rewritten to use tree-sitter AST analysis instead of relying solely on string-based heuristics. When tree-sitter is available, it provides authoritative quote context analysis, compound structure detection, and dangerous pattern identification.

New security checks include:

  • Arithmetic expansion with variable references
  • Heredocs with unquoted delimiters (shell expansion risk)
  • Brace expansion syntax detection
  • IFS assignment (word-splitting changes)
  • Tilde expansion in assignment values
  • Unicode whitespace and control character detection
  • Zsh ~[ dynamic directory syntax
  • Shell keyword misuse detection

When tree-sitter is unavailable, falls back to the legacy shell-quote parser with a log message: "tree-sitter unavailable, using legacy shell-quote path".

Evidence

New analyzer functions (search for "Tree-sitter quote context is authoritative", "Brace expansion", "IFS assignment")

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

See this entry in the whole of v2.1.72 →