Environment
- Claude Code 2.1.232 (native install), Windows 11 Pro, Git Bash shell
- Observed independently on two separate machines (different users, different hardware, same day)
- Onset correlates exactly with 2.1.232 arriving via the native launcher's startup self-update (version files on disk: 2.1.229 → 13 Aug 08:30, 2.1.231 → 13 Aug 09:41, 2.1.232 → 14 Aug 06:01 local; prompts began within hours on both machines), compounding with the 14 Aug auto-mode default rollout.
What happens
On Windows with Git Bash, any Bash command of the shape cd "<absolute path>" && <anything not fully literal> now fails static analysis and falls through to a manual "Do you want to proceed?" prompt. We have collected four distinct reason wordings verbatim:
-
Contains simple_expansion On Windows with Git Bash, the final working directory of this cd-compound cannot be statically determined, so relative write targets cannot be checked for Cygwin-emulated symlinks and this request cannot be delegated to the auto-approval classifier.
-
Redirect target contains $(cmd) output — path is runtime-determined On Windows with Git Bash, [same continuation]
-
Contains brace with quote character (expansion obfuscation) On Windows with Git Bash, [same continuation]
-
Compound command contains cd with write operation - manual approval required to prevent path resolution bypass On Windows with Git Bash, [same continuation]
The clearest false positive
Reason 4 above was produced by this command, which contains no write operation of any kind — two sed -n reads and a pipe:
cd "C:/Users/<user>/<project>" && sed -n '/pattern-a/,/pattern-b/p' static/app.js | sed -n 1,60p
Other innocuous shapes reliably prompting:
# read-only loop → "Contains simple_expansion"
cd "C:/Users/<user>/<project>" && for v in 1.60.0 1.58.0; do echo "== $v"; uv run --with "pkg==$v" python -c "..." 2>&1 | tail -2; done
# write to a FULLY ABSOLUTE literal temp path via variable → "Redirect target contains $(cmd) output"
cd "C:/Users/<user>/<project>" && S="C:/Users/<user>/AppData/Local/Temp/claude/<session>/scratchpad" && tool > "$S/out.json" 2>&1
# heredoc script to an absolute literal path → "expansion obfuscation"
cd "C:/Users/<user>/<project>" && cat > "C:/.../scratchpad/probe.py" <<'PY'
...
PY
Note the cd target is always a quoted absolute path, so the "final working directory cannot be statically determined" claim is itself questionable for these commands.
Why the friction is severe
Expected behaviour
- A command whose parts are all read-only (
sed -n, grep, head, tail, pipes, no redirects) should pass static analysis regardless of cd, or at minimum remain delegable to the auto-approval classifier.
- A command containing no redirect and no write verb should never be described to the user as containing a "write operation".
cd to a quoted absolute path should establish the working directory for the analysis of the rest of the compound.
- Where the analyser can identify the offending sub-part (it already prints "The following part requires approval: …"), the prompt should offer a scoped "don't ask again".
Happy to provide more captures — we are logging every distinct wording.
Environment
What happens
On Windows with Git Bash, any Bash command of the shape
cd "<absolute path>" && <anything not fully literal>now fails static analysis and falls through to a manual "Do you want to proceed?" prompt. We have collected four distinct reason wordings verbatim:The clearest false positive
Reason 4 above was produced by this command, which contains no write operation of any kind — two
sed -nreads and a pipe:Other innocuous shapes reliably prompting:
Note the cd target is always a quoted absolute path, so the "final working directory cannot be statically determined" claim is itself questionable for these commands.
Why the friction is severe
cd "<abs>" && ...compounds constantly (it is the natural way to scope a command to a project). Users are seeing dozens of prompts per hour during normal agentic work.Bash(cmd *)allow rules in settings help, but only apply to sessions started after they are saved."autoUpdates": false).Expected behaviour
sed -n,grep,head,tail, pipes, no redirects) should pass static analysis regardless ofcd, or at minimum remain delegable to the auto-approval classifier.cdto a quoted absolute path should establish the working directory for the analysis of the rest of the compound.Happy to provide more captures — we are logging every distinct wording.