Claude Code Fixes Deny Rule and Tool Restriction Gaps

Claude CodeView original changelog

Claude Code 2.1.295 closes several gaps where a user-configured guardrail did not block what it should. A Chrome site deny rule written with port 80 was ignored on plain http pages, --tools and --restricted missed late-registering built-in tools, and some mod guard hooks could be bypassed or shown truncated input. A Bash permission check for for-loops over globs was also tightened.

Key Takeaways

  • A Chrome deny rule written as host:80 was not blocking plain http pages on that host, and now does.
  • --tools and --restricted now apply to built-in tools that register after launch, so restricted sessions stay restricted.
  • Deprecated tool names can no longer reach tools outside the caller's tool set.
  • A mod guard hook could previously be given truncated, deeply nested tool input with no error, letting it approve content it never saw.
  • Calls made during a plugin hooks worker restart could bypass another mod's guard hook, and are now refused.
  • A Bash for-loop over glob patterns permission check was tightened for accuracy.

Guardrails that did not block

Claude Code 2.1.295 includes a cluster of fixes where a rule the user had set up failed to stop something it was meant to stop. Individually they are small, but together they follow the pattern of earlier permission hardening releases: the agent could act outside what had been authorized.

Chrome site deny rules with port 80

A site deny rule written with port 80 (host:80) was not applied to plain http:// pages on that host. Someone who had denied a site using the explicit port form could still have Claude in Chrome reach the same host over ordinary http. The rule now applies to those pages.

Tool restrictions that missed late tools

The --tools and --restricted options did not apply to built-in tools that register after launch, and deprecated tool names could reach tools outside the caller's tool set. Both cases are fixed, so a restricted session stays restricted even for tools that appear after startup.

Bash permission checks for glob loops

Permission checks for Bash for-loops over glob patterns were corrected to improve accuracy, so those commands are evaluated against permission rules more reliably.

Mod guard hooks

Two fixes concern mods that act as guards. A mod's hook could be handed a deeply nested tool input that was cut short with no error, meaning a guard could approve content it never actually saw. Separately, calls made by a mod while it reloaded during a plugin hooks worker restart could slip past another mod's guard hook that had a .catch. Such calls are now refused.

Who should care

Anyone relying on deny rules, restricted tool sets, or guard hooks to bound what Claude Code may do should update to 2.1.295. The Chrome port-80 and --tools/--restricted fixes affect everyday configurations, while the mod fixes matter for teams that use mods to enforce policy.