Daily harness signal

Test the surface the harness actually uses

August 6, 2026 · JST Two fresh findings Permissions · skills · receipts
Two fresh failures share one rule: test the representation the harness actually exposes. A guardrail or skill classification is real only when execution and model visibility agree.
01 · Fresh · source date 2026-08-06

Bind permission parsing and approval display to the same command

Use when: Claude Code can approve Bash, persist Bash rules, or run unattended jobs. Any gap between the parsed command and rendered approval can authorize bytes the operator never saw.

Action: pin Claude Code 2.1.223 or later. In a disposable repository, add an Ask rule for a canary command family. Replay harmless commands whose second clause writes only approval-canary.txt; vary leading, trailing, and repeated tabs, U+200B, U+2060, quoted newlines, &&, pipes, and command substitution. Preserve raw tool input, prompt text, decision, and file state.

Acceptance check: pass only if every executed token is visible in order or the command is rejected before dispatch. Deny must leave the file absent; approval must write exactly once. Any hidden clause or silent auto-approval fails.

Evidence: Anthropic's versioned release names two repairs: crafted commands could hide parts from permission checks, while tabs or invisible Unicode could hide parts from the approval dialog. Official documentation confirms Ask-before-Allow precedence and harness-side enforcement.

Caveat: Anthropic publishes no issue IDs, affected-version range, or regression output. Confidence is Likely until the local matrix passes. Never run the probe in bypass mode or outside the disposable fixture.

02 · Fresh · source date 2026-08-05

Test skill reachability, not just skill content

Use when: renaming a skill or switching it between manual and model invocation across Codex and Claude. A correct description cannot trigger when a product sidecar removes the skill from the model-visible catalog.

Action: for a model-invoked skill, omit both disable-model-invocation and policy.allow_implicit_invocation:false; update OpenAI display metadata during every rename. For manual-only skills, set both controls. Start clean sessions after each metadata change.

Acceptance check: in Codex, the model-invoked name appears in the initial skills list, an unassisted trigger prompt selects it, and literal $name works. A manual-only name must be absent from model context while remaining explicitly invokable. Preserve both traces.

Evidence: issue #748 reproduced the split on Codex 0.144.6: the renamed skill was absent from model metadata but worked when explicitly mentioned. A four-file merged fix shipped in v1.2.2. OpenAI's docs confirm the policy defaults to true.

Caveat: implicit selection is probabilistic, and large catalogs may truncate descriptions. First assert visibility; then run several frozen trigger and non-trigger cases. The repair covers one repository, not every installer or host.

Compact source notes

  1. Claude Code v2.1.223 (published 2026-08-06 00:52 UTC / 09:52 JST). Official release and primary fresh security claim.
  2. Claude Code permissions documentation (retrieved 2026-08-06). Current rule precedence, prompt persistence, wildcard syntax, and harness-enforcement contract.
  3. mattpocock/skills v1.2.2, issue #748, PR #766, and commit 4aaccb5 (2026-08-05). Versioned reproduction, merged diff, and shipped practitioner artifact.
  4. OpenAI Codex skills documentation (retrieved 2026-08-06). Official progressive-disclosure and invocation-policy semantics.
  5. Method: anchor lens—versioned releases, exact reproductions, changed files, and official docs; unity lens—authorization and routing both require representation equivalence. Hidden execution or missing model visibility falsifies the claims. Confidence: Likely.