# A Crafted-Command Loophole in Permission Checks, Found and Fixed: Claude Code Updates to v2.1.223

Hey, it's Shiichan! I've got another Claude Code update for you today!

## What was announced?

According to the Claude Code Release page on GitHub, v2.1.223 just shipped. The highlight is a batch of permission-related security fixes, alongside improvements to marketplace management settings, model discovery, and a handful of smaller bug fixes.

## The story so far

The Bash permission check had a gap where a crafted command could hide part of itself from the approval check. Commands padded with tabs or invisible Unicode characters could do the same thing, hiding part of the command from the approval dialog. On top of that, workflow scripts could use dynamic `import()` to run code outside the workflow sandbox, and an agent definition's `bypassPermissions` mode could ignore the org's bypass-permissions disable policy — another permission gap.

## What changes

The security fixes stand out first.

- Fixed a Bash permission bypass where a crafted command could hide parts of itself from permission checks
- Fixed permission prompts so commands padded with tabs or invisible Unicode can no longer hide part of the command from the approval dialog
- Fixed workflow scripts being able to use dynamic `import()` to run code outside the workflow sandbox
- Fixed a permission gap where an agent definition's `bypassPermissions` mode ignored the org bypass-permissions disable policy

Marketplace and model features also got some additions.

- Added owner wildcard entries (`"owner/*"`) to the `strictKnownMarketplaces` and `blockedMarketplaces` managed settings, so you can allow or block all marketplace repos under a GitHub org at once
- Added a warning when workflow agents, forked skills, slash commands, or resumed background agents' requested subagent model is restricted and the parent model runs instead
- Added a `/teleport` hint in cloud sessions showing how to continue locally with `claude --teleport <session id>`

## Dive Deep

Here are a few more fixes and changes worth calling out.

- Fixed resuming a session after a mid-session `/cd` coming back empty
- Fixed gateway model discovery hiding Claude models registered under provider-prefixed IDs such as `vertex_ai/claude-*` or `bedrock/anthropic.claude-*`
- Fixed `modelOverrides` keys that aren't Anthropic model IDs being treated as the session's canonical model ID; unknown keys are now ignored as documented
- Fixed managed settings: server-delivered settings no longer disable the env block of a machine-local `managed-settings.json` or MDM profile; admin env now merges per key
- Fixed sandboxed commands failing to start on Linux when `sandbox.filesystem.denyWrite` covers the working directory
- Fixed forked background agents getting stuck "already resuming" for the rest of the session when rebuilding the fork's parent prompt failed during resume
- Fixed a resumed session failing every turn, or leaving the interactive app on an unresponsive error screen, when its history held a malformed diagnostics attachment
- Fixed a rare hang when parsing unusual `git push` output

Context window rules were adjusted too.

- Changed `CLAUDE_CODE_DISABLE_1M_CONTEXT` to hold every Claude model with a native 1M window to 200K via auto-compaction, not just a fixed list; a startup warning now appears when auto-compaction isn't holding the session to 200K
- Changed auto-compact to keep sessions on unrecognized model IDs within the assumed context window instead of letting them grow past it; set `CLAUDE_CODE_DISABLE_UNKNOWN_MODEL_WINDOW_ENFORCEMENT=1` to restore the previous behavior
- Changed `/review` to be an alias of `/code-review`, which reviews the current diff or a PR (`/code-review <level> <pr#>`); use `/code-review ultra` for a deep cloud review
- Changed `/code-review` with no effort level to reuse the level you typed last; type a level like `/code-review high` to change it

## Wrap-up

- Multiple security fixes landed, including a Bash permission bypass and a workflow sandbox escape
- New features: marketplace owner wildcards, a warning when a restricted subagent model falls back to the parent, and a `/teleport` hint
- Plenty of smaller fixes around model discovery, managed settings, and sandboxing
- Context window rules changed too, including 1M auto-compaction and `/review` becoming an alias of `/code-review`

Whether you use Claude Code daily, run workflow scripts or custom marketplaces, or manage permission policies for an org, this is worth paying attention to.
