Shell commands could hide part of themselves from the approval prompt, in the fortnight the prompt stopped being the default
Four holes of one shape closed across v2.1.221 and v2.1.223: a Bash permission-check bypass where zsh could execute hidden commands inside regex conditionals, PowerShell checks mishandling paths containing quote characters on Windows, a crafted command that could hide parts of itself from the permission check, and commands padded with tabs or invisible Unicode hiding part of themselves from the approval dialog. A fifth defect of a different shape landed in v2.1.224: sandbox deny entries written with a trailing slash, such as denyRead for a credentials directory, were silently bypassable on Linux and macOS. Channel is the npm publish record rather than git ancestry, because the source is closed; the versions are plain semver under the latest dist-tag.
What this changes for operators
- Upgrade past 2.1.224, then re-read your own sandbox deny rules for trailing slashes. That defect invalidated configuration an operator wrote and believed in, and nothing surfaced the failure.
- Approval logs from before this window are evidence of what was asked, not of what ran. If you retain transcripts for audit, the recorded approval and the executed command can differ, and no artifact you hold identifies which sessions were affected.
- Enumerate custom agent definitions: a separate fix closed an agent definition whose bypass mode ignored an organisation policy that had disabled it.
Signal metadata
Source findings
- 2026-08-10-claude-code-claude-code-shell-commands-could-hide-part-of-themselves-from-the 2026-08-10-claude-code-claude-code-shell-commands-could-hide-part-of-themselves-from-the
Run: 2026-08-10-weekly-digest-2026-08-03_2026-08-10-frontier-v0
Schema: bitter.frontier_signals.v0 / ID: 2026-08-10-claude-code-commands-could-hide-from-their-own-prompt
Research evidence and publication history are open in the repository.