Show HN: First-token-only flaw in Claude Code permissions (triage bot too)(spitfirecowboy.com)
spitfirecowboy.com
Show HN: First-token-only flaw in Claude Code permissions (triage bot too)
https://spitfirecowboy.com/workshop/0008-the-receipt-was-lying/
But that is exactly wrong. Allow and deny lists allow DANGEROUS actions like "git cleanup"
Some human needs to read this HN post and my blog post. I've written a bash-guard fix that I use locally, but I CAN'T help everyone else until Anthropic takes my bug report seriously
https://github.com/anthropics/claude-code/issues/36637 https://github.com/anthropics/claude-code/pull/36645