The Lab Notes

Anthropic

Claude Code fixes dangerous rm commands running without a prompt

Claude Code 2.1.288 fixes a dangerous rm inside bash -c and sh -c scripts running without a prompt in bypassPermissions mode or under a shell allow rule.

An open pink and gold padlock with its shackle raised, tilted on a yellow and purple grid background, with two red rods pointing at it from the left and white motion lines around it.

Anthropic has fixed a case in which Claude Code ran a dangerous rm, such as one aimed at / or the home directory, without a prompt when the command sat inside a bash -c or sh -c script. The changelog does not say how long the gap existed or whether anyone was affected.

The fix is in Claude Code 2.1.288, according to the entry dated Oct. 2, 2026 on the Claude Code changelog at code.claude.com. The npm registry shows the release published at 18:30 UTC that day, after 2.1.287 on Oct. 1 and 2.1.286 on Sept. 30. The npm “latest” and “next” tags point to 2.1.288, while “stable” is still 2.1.285.

The gap covered wrapped commands

The changelog entry dated Oct. 2 says the fix applies to a dangerous rm inside a bash -c or sh -c script “running without a prompt in bypassPermissions mode or under a shell allow rule.” It cites anthropics/claude-code#96300.

The entry does not say what that issue describes.

Other permission and sandbox fixes shipped alongside

A Bash permission check now prompts before a BASHPID assignment whose value the shell would evaluate as arithmetic, where it previously allowed the assignment silently, according to the changelog entry.

Sandboxed heredocs with an unquoted delimiter, such as python3 <<EOF, no longer ask for approval on every run under sandbox auto-allow when the body holds only plain text and simple $VAR references. Entries on git config files in sandbox.credentials.files now take effect while permissions.blockReadsOutsideWorkingDirectories is on.

Auto mode denials also stop pointing Claude at a Bash permission rule when the blocked tool was not Bash.

The rest of the release is small

Claude Code 2.1.288 is mostly fixes, with a handful of small additions. The Up arrow now recovers a prompt that Ctrl+C cleared. Claude Code shows a re-authenticate prompt when an MCP server asks for more OAuth scope mid-call. The /code-review command takes --max-findings <n>|all, and Ctrl+F finds a session by name in the agents view.

The previous release, 2.1.287, added Claude Mods, according to the changelog entry dated Oct. 1, 2026.

Analysis

We think this fix matters most to people who have turned the prompts off. A prompt is the moment Claude Code stops and asks before it runs a command. In bypassPermissions mode, or under a broad shell allow rule, that moment is skipped on purpose, so the safety check on rm is the last thing standing between a bad command and deleted files.

It helps to know what the wrapper does. bash -c hands a whole script to a new shell as one string of text, so the rm sits inside that string instead of at the front of the command. The changelog says that is the case the fix covers.

The changelog does not say whether anyone lost files. Anyone who skips prompts should update past stable 2.1.285, which does not carry the fix.