Claude Code: Permission and Sandbox Gaps Closed Across Auto Mode, UNC Reads and Skills
Claude Code 2.1.292 closes a batch of gaps where the agent could act beyond what a user authorized, including network (UNC) file reads that skipped the permission prompt and subagents entering auto mode when it was unavailable. Several sandbox read-deny and link-swap issues were fixed alongside them.
Key Takeaways
- UNC network reads now prompt, because PreToolUse hook approvals and auto mode no longer bypass the permission check for them.
- Subagents with
permissionMode: autono longer enter auto mode when it is unavailable, including when settings or a circuit breaker disable it. - A skill's
allowed-toolsrule no longer returns in a later turn after leaving auto or plan mode mid-turn. - Compaction summaries can no longer trigger user-reserved skills by repeating a
/name. - Sandbox fixes cover
/ultrareviewstaged copies, mid-session read-deny changes, and link swaps during notebook and PDF reads. rm -rfon Windows 8.3 short names and alternate home-folder spellings is now treated as the destructive command it is.
A cluster of trust-boundary fixes
Claude Code 2.1.292 patches a group of issues in which the agent could do something outside what a user had approved. Together they follow the pattern of the previous days' releases: permissions, sandbox rules and auto mode are tightened where they behaved more permissively than documented.
Permission prompts and auto mode
PreToolUse hook approvals and auto mode could previously bypass the permission prompt for file reads from network (UNC) paths. That is fixed, and these reads now prompt as expected. Separately, subagent definitions that set permissionMode: auto could enter auto mode even when auto mode was unavailable, whether because settings disabled it, a circuit breaker had tripped, or the model did not support it. They no longer do.
Two further fixes affect how permissions persist. A skill's or slash command's allowed-tools rule could come back in a later turn after a user left auto mode or plan mode partway through the turn, and that no longer happens. A compaction summary that repeated a /name could also let Claude invoke a skill reserved for the user, which is now blocked.
Sandbox and file access
Sandboxed commands could read the staged file copies of /ultrareview uploads under ~/.claude/seed-admin, which is now prevented. When a managed sandbox read-deny path, or a user one beside it, appeared or was re-pointed mid-session, project grants inside it were not dropped and credential injection from files it covered did not end. Both now update correctly.
On macOS and Windows, a notebook or PDF read could return a file outside what was approved if a link was swapped in mid-read. That window is closed. A tampered on-disk cache of server-managed settings could also switch off or unseat the built-in policy plugin while the settings fetch failed, and this is fixed.
Destructive command detection on Windows
rm -rf on the 8.3 short name or another alternate Windows spelling of the home folder or a drive was not treated as removing it, so the usual safeguards could be skipped. Those spellings are now recognized.