Claude Code Closes rm, BASHPID and Fail-Open Hook Gaps in Permission Checks
Claude Code 2.1.288 patches four gaps where the agent could act outside what the user authorized. A dangerous rm inside a bash -c script could run unprompted in bypassPermissions mode or under a shell allow rule, a BASHPID arithmetic assignment slipped past the prompt, hooks that failed to match were skipped, and sandbox credential file entries on git config files were ignored under one setting. Updating closes all four.
Key Takeaways
- A dangerous
rminsidebash -corsh -cno longer runs unprompted in bypassPermissions mode or under a shell allow rule. BASHPIDassignments evaluated as arithmetic now trigger a permission prompt instead of passing silently.- Broken PreToolUse and PermissionRequest hooks now block the call, so policy checks fail closed rather than being skipped.
sandbox.credentials.filesentries on git config files now work even withblockReadsOutsideWorkingDirectoriesenabled.- The fixes continue a week-long run of permission hardening, following the 2.1.287
rmredirect safeguard. - Anyone using bypassPermissions or broad allow rules gains the most from updating to 2.1.288.
Four trust-boundary fixes in one release
Claude Code 2.1.288 includes four fixes that all concern the same question: could the agent do something the user had not authorized? Each one is now closed.
Dangerous rm hidden in bash -c
A dangerous rm, such as one targeting / or the home directory, could run without a prompt when it was wrapped inside a bash -c or sh -c script. This applied in bypassPermissions mode and under a shell allow rule. Claude Code 2.1.288 now recognizes the destructive command inside the wrapped script and asks first. This follows a fix in 2.1.287 that restored the always-ask safeguard for rm when the same command also redirected output to a ~ or wildcard path.
BASHPID arithmetic assignment
The Bash permission check now prompts before a BASHPID assignment whose value the shell would evaluate as arithmetic. Previously such an assignment was allowed silently, even though evaluating arithmetic can execute embedded expressions.
Hooks that fail now block instead of skipping
PreToolUse and PermissionRequest hooks were skipped when matching them failed or when the tool's input could not be serialized to JSON. That meant a policy hook could quietly not run. In 2.1.288 the call is blocked instead, so a broken hook fails closed rather than open.
Sandbox credential files on git config
Entries under sandbox.credentials.files that pointed at git config files did not take effect while permissions.blockReadsOutsideWorkingDirectories was turned on. They now apply as configured, so the intended credential protection holds.
What to do
All four fixes ship in 2.1.288. Teams that rely on bypassPermissions, shell allow rules, policy hooks or sandbox credential protection should update promptly.