First-token-only flaw in Claude Code permissions (triage bot too)
First-token-only flaw in Claude Code permissions (triage bot too)
I filed GH issues, and PR fixed on claude-code. I submitted a report on Hackerone, but the triage bot has the SAME category error problem. I got dismissed as "informatiional" because your bot saw my 'rm -rf' example, and dismissed it as an OS problem. But that is exactly wrong. Allow and deny lists allow DANGEROUS actions like "git cleanup" Some human needs to read this HN post and my blog post. I've written a bash-guard fix that I use locally, but I CAN'T help everyone else until Anthropic takes my bug report seriously https://github.com/anthropics/claude-code/issues/36637 https://github.com/anthropics/claude-code/pull/36645
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Correct prediction on native model
Similar products
Ccperm – Audit Claude Code permissions across projects
Promode for Claude Code
Durin – A Permissions Guardian
Derek GitHub bot that delegates fine-grained permissions
Reduce Claude Code token usage ~50% with Headroom
Iantha – build your own Jarvis on Claude Code
Checkpoints for Claude Code [video]
Oyster Bot – AI assistant for your phone, powered by Claude Code
Config manager for Claude Code (and others) – rules, MCPs, permissions
Permissions Tool for SysPass