Claude Code Closes Auto-Approve and Prompt-Check Gaps in BASH_ARGV0, Interrupted Hooks and Git Bash rm
Claude Code 2.1.296 patches a batch of cases where the agent could act outside what a user authorized. Bash commands that assign BASH_ARGV0 and then use it are no longer auto-approved, an Esc or interrupt during a prompt-submit hook can no longer let an unchecked prompt through, and managed hooks that deny a tool call now end the turn properly. The release also restores the ask prompt for rm -rf on a Windows user folder in Git Bash under bypass permissions mode, and makes cloud sessions run auto mode's checks on Claude in Chrome actions even before feature flags load.
Key Takeaways
- Bash commands that assign
BASH_ARGV0and then use it now require approval, closing a way to disguise a command from automatic approval checks. - An Esc or interrupt during a
UserPromptSubmitorprompt.submithook could let an unchecked prompt through, and Claude Code 2.1.296 fixes that. - Managed
PreToolUsedeny hooks and blockingprompthooks now end the turn, instead of refusing the call and letting the turn continue. rm -rf /c/Users/<name>in Git Bash asks for confirmation again in bypass permissions mode on Windows.- Cloud sessions now run auto mode's checks on Claude in Chrome actions even when feature flags have not loaded.
- The VS Code extension asks before browser actions in every session, including
@browsersessions, and allowing a site for the session stops repeat asks.
Sources & Mentions
4 external resources covering this update
A release focused on the permission boundary
Claude Code 2.1.296 contains a cluster of fixes that all answer the same question: could the agent do something the user never approved? Each one closes a path where a check was skipped, a block was ignored, or a prompt was never shown. Taken together they matter more than most individual features, because they decide whether approval prompts and managed policies can be trusted.
Shell commands that slipped past approval
BASH_ARGV0 assignments now prompt
Bash permission checks previously auto-approved some commands that assigned the BASH_ARGV0 shell variable and then used it. That variable changes how bash reports the name of the running command, which makes it a useful way to disguise what a command is really doing. Claude Code 2.1.296 now asks for approval on these commands instead of letting them run automatically.
rm -rf on a Windows user folder in Git Bash
On Windows, rm -rf /c/Users/<name> run through Git Bash did not ask for confirmation when Claude Code was in bypass permissions mode. The release fixes that, so a recursive delete of a user's home folder prompts again even in the mode designed to skip most prompts.
Hooks that failed to stop what they were meant to stop
Interrupting a prompt-submit hook
A UserPromptSubmit hook, or a mod's prompt.submit hook, is often used to screen what a user types before it reaches the model. Pressing Esc or sending an interrupt while one of these hooks was running could end a headless session, clear the typed prompt, or let the unchecked prompt through. Claude Code 2.1.296 fixes the interrupt handling so a prompt that a screening hook has not approved is not sent on.
Managed deny hooks now end the turn
In managed settings, a PreToolUse hook that denies a tool call with "continue": false, and a managed prompt hook that blocks a call, refused the call but did not end the turn. The turn now stops as the policy author intended.
Auto mode checks in cloud sessions
Cloud sessions could skip auto mode's checks on Claude in Chrome actions that a saved permission allows, when their feature flags had not loaded. The checks now run in that situation as well.
Claude in Chrome asks in every VS Code session
In the VS Code extension, Claude in Chrome now asks before browser actions in every session, including a session connected with @browser, matching what the terminal already did. Allowing a site for the session stops repeat asks, so the added prompts do not repeat for the same site.
Why it matters
None of these fixes adds a new feature, but each one narrows the gap between what a user or administrator configured and what the agent could actually do. Teams that rely on managed hooks, bypass mode on Windows, or hook-based prompt screening should update to 2.1.296.