Claude Code: Shell Write Safeguards Tightened for rm, Symlinks and Credential Files
Claude Code 2.1.287 closes several gaps where shell commands could write outside what the user approved. A dangerous rm no longer loses its always-ask safeguard when it also redirects output to a home or wildcard path, writes through repo-committed symlinks now wait for a person, and broad Bash allow rules no longer let shell writes reach credential files that Claude's file tools refuse.
Key Takeaways
- A dangerous rm keeps its always-ask safeguard even when the same command also redirects output to a
~or wildcard path. - Shell writes through repo-committed symlinks now wait for a person, and the prompt names the real destination of the write.
- Whole-tool Bash allow rules and allowing hooks now prompt for shell writes to files Claude's own file tools refuse, such as the credentials file.
- The fixes target cases where the agent could act outside what the user authorized, which is the core trust boundary of Claude Code.
- Org permission ceilings were silently dropped for an MCP tool named
__proto__, a gap that is now closed. - Bash permission prompts now use plain explanations instead of internal parser names like "Contains simple_expansion".
Why These Fixes Matter
Claude Code 2.1.287 includes a cluster of changes to the permission layer for shell commands. Each one concerns a case where Claude could have acted outside what the user authorized, which is why they matter to anyone running Claude Code with allow rules or in auto mode.
Dangerous rm Keeps Its Always-Ask Safeguard
Claude Code always asks before running a dangerous rm, such as one aimed at / or the home directory. A bug removed that safeguard when the same command also redirected output to a path starting with ~ or containing a wildcard. The safeguard now holds in that case, so the destructive part of a compound command is still surfaced for approval.
Writes Through Committed Symlinks Wait for a Person
A repository can commit a symlink that points at a sensitive file or at a location outside the working tree. Claude Code now treats a shell write through such a symlink as something that needs a human decision: the prompt names where the write actually lands and waits. This also applies to command lines that use a ~ target.
Allow Rules No Longer Reach Credential Files
Claude Code's own file tools refuse certain targets outright, including the Anthropic profile store and the host credentials file. Previously, a whole-tool Bash allow rule or an allowing hook could let a shell command write to those same files. Such writes now prompt instead of running, closing the gap between the file tools and the shell.
Related Hardening
The same release fixes organization per-tool permission ceilings being silently dropped for an MCP tool named __proto__, and stops sandboxed Bash commands on Linux from inheriting an open handle on the Claude Code executable. Bash permission prompts also now explain what triggered them in plain words instead of showing internal parser names such as "Contains simple_expansion".