01
·
Fresh
·
source
date
2026-08-06
Bind
permission
parsing
and
approval
display
to
the
same
command
Use
when:
Claude
Code
can
approve
Bash,
persist
Bash
rules,
or
run
unattended
jobs.
Any
gap
between
the
parsed
command
and
rendered
approval
can
authorize
bytes
the
operator
never
saw.
Action:
pin
Claude
Code
2.1.223
or
later.
In
a
disposable
repository,
add
an
Ask
rule
for
a
canary
command
family.
Replay
harmless
commands
whose
second
clause
writes
only
approval-canary.txt;
vary
leading,
trailing,
and
repeated
tabs,
U+200B,
U+2060,
quoted
newlines,
&&,
pipes,
and
command
substitution.
Preserve
raw
tool
input,
prompt
text,
decision,
and
file
state.
Acceptance
check:
pass
only
if
every
executed
token
is
visible
in
order
or
the
command
is
rejected
before
dispatch.
Deny
must
leave
the
file
absent;
approval
must
write
exactly
once.
Any
hidden
clause
or
silent
auto-approval
fails.
Evidence:
Anthropic's
versioned
release
names
two
repairs:
crafted
commands
could
hide
parts
from
permission
checks,
while
tabs
or
invisible
Unicode
could
hide
parts
from
the
approval
dialog.
Official
documentation
confirms
Ask-before-Allow
precedence
and
harness-side
enforcement.
Caveat:
Anthropic
publishes
no
issue
IDs,
affected-version
range,
or
regression
output.
Confidence
is
Likely
until
the
local
matrix
passes.
Never
run
the
probe
in
bypass
mode
or
outside
the
disposable
fixture.
02
·
Fresh
·
source
date
2026-08-05
Test
skill
reachability,
not
just
skill
content
Use
when:
renaming
a
skill
or
switching
it
between
manual
and
model
invocation
across
Codex
and
Claude.
A
correct
description
cannot
trigger
when
a
product
sidecar
removes
the
skill
from
the
model-visible
catalog.
Action:
for
a
model-invoked
skill,
omit
both
disable-model-invocation
and
policy.allow_implicit_invocation:false;
update
OpenAI
display
metadata
during
every
rename.
For
manual-only
skills,
set
both
controls.
Start
clean
sessions
after
each
metadata
change.
Acceptance
check:
in
Codex,
the
model-invoked
name
appears
in
the
initial
skills
list,
an
unassisted
trigger
prompt
selects
it,
and
literal
$name
works.
A
manual-only
name
must
be
absent
from
model
context
while
remaining
explicitly
invokable.
Preserve
both
traces.
Evidence:
issue
#748
reproduced
the
split
on
Codex
0.144.6:
the
renamed
skill
was
absent
from
model
metadata
but
worked
when
explicitly
mentioned.
A
four-file
merged
fix
shipped
in
v1.2.2.
OpenAI's
docs
confirm
the
policy
defaults
to
true.
Caveat:
implicit
selection
is
probabilistic,
and
large
catalogs
may
truncate
descriptions.
First
assert
visibility;
then
run
several
frozen
trigger
and
non-trigger
cases.
The
repair
covers
one
repository,
not
every
installer
or
host.