Claude Code Closes Permission Gaps in Plan Mode Forks, Artifacts and PowerShell

Claude CodeView original changelog

Claude Code 2.1.285 closed another batch of gaps in its permission and sandbox boundary. Fork subagents now keep the parent session's plan mode and dontAsk mode, project settings can no longer weaken an admin-required sandbox, and the PowerShell tool no longer skips deny and ask rules when its parser fails to start. Several Artifact tool approval and overwrite gaps were also fixed.

Key Takeaways

  • Fork subagents now inherit plan mode and dontAsk mode, and cannot exit plan mode on their own.
  • Project settings can no longer weaken an admin-required sandbox, including managed deny lists, allowlists and read-denies.
  • The PowerShell tool no longer skips deny and ask rules when its command parser fails to start.
  • An Artifact allow rule no longer covers files outside the working directories unless the folder is added with --add-dir.
  • Auto mode now runs its classifier on Artifact uploads and reads of other people's artifacts approved in a different mode.
  • A reply from claude agents can no longer approve a pending permission prompt in a background session by accident.

Permission and sandbox fixes in Claude Code 2.1.285

Claude Code 2.1.285 continues Anthropic's run of trust-boundary fixes, this time covering subagents, sandbox policy, the PowerShell tool and the Artifact tool. Each of these describes a case where the agent could act outside what a user or administrator had authorized.

Subagents and approvals

Fork subagents did not keep the session's plan mode or dontAsk mode. A fork now runs under its parent's permission mode and cannot exit plan mode, so a session that was meant to only plan can no longer have a fork act on the code. A related fix covers claude agents: a reply sent to a background session that was waiting on a permission prompt could sometimes approve the pending command by accident. That no longer happens.

Sandbox policy set by administrators

Project settings can no longer widen or turn off an admin-required sandbox, replace the proxy behind a managed deny list, extend a strict allowlist, or reopen managed read-denies. Organizations that rely on a managed sandbox now get the guarantee that a repository's own settings file cannot loosen it.

PowerShell tool

When the PowerShell tool's command parser failed to start, for example because the machine was out of memory, its permission check skipped deny and ask rules and cached that failure for later checks. The check now behaves correctly in that situation.

Artifact tool

Three Artifact fixes affect approvals. An Artifact allow rule ("don't ask again") let the tool publish a file outside the working directories without asking; the folder must now be added with --add-dir for the rule to cover it. Auto mode also skipped its classifier for Artifact asset uploads and for reads of someone else's artifact when that artifact had been approved earlier in another permission mode. Separately, publishing after a conversation rewind could overwrite a file's newer content that Claude had only read in the rewound turns; the publish is now refused until Claude re-reads the file.