From a726f0dd95e0259da3537143c4b270087719538f Mon Sep 17 00:00:00 2001 From: Marta Anon Date: Fri, 17 Jul 2026 12:43:12 +0200 Subject: [PATCH] docs: annotate experiment 0021 with post-v2.1.119 corrections The experiment ran on v2.1.118; v2.1.119 (released 21 hours later) changed tools/disallowedTools enforcement. Add dated correction notes and strikethrough on stale claims, cross-referencing the RCA. Related to RCA (Root Cause Analysis) [#5182](https://github.com/fullsend-ai/fullsend/discussions/5182) Co-Authored-By: Claude Opus 4.6 Signed-off-by: Marta Anon --- 0021-tool-scoping/README.md | 24 +++++++++++++++++++----- 1 file changed, 19 insertions(+), 5 deletions(-) diff --git a/0021-tool-scoping/README.md b/0021-tool-scoping/README.md index 407d77b..e4450ea 100644 --- a/0021-tool-scoping/README.md +++ b/0021-tool-scoping/README.md @@ -17,17 +17,25 @@ with `claude --agent`. | Mechanism | Parameterized? | `--agent` session | Subagent | |-----------|---------------|-------------------|----------| -| `tools` in frontmatter | No | **No effect** | Restricts to listed tools | -| `disallowedTools` in frontmatter | No | **No effect** | Removes listed tools | +| `tools` in frontmatter | No | ~~**No effect**~~ see note | Restricts to listed tools | +| `disallowedTools` in frontmatter | No | ~~**No effect**~~ see note | Removes listed tools | | `permissions.allow` in settings.json | **Yes** | **Enforced** (with `dontAsk`) | — | | `permissions.deny` in settings.json | **Yes** | **Enforced** (even with `--dangerously-skip-permissions`) | — | | `bypassPermissions` mode | N/A | **Partial** — auto-approves some tools, denies others | — | +> **Note (2026-07):** This experiment ran on v2.1.118. Claude Code +> v2.1.119, released 21 hours later, changed enforcement: `tools` and +> `disallowedTools` are now applied in `--agent`/`--print` sessions. +> However, multiple bugs make them unreliable — scoped patterns like +> `Bash(sed *)` strip the entire tool, and subagents don't inherit +> restrictions. See RCA (Root Cause Analysis) +> [#5182](https://github.com/fullsend-ai/fullsend/discussions/5182). + ## 1. Frontmatter scoping (`tools`, `disallowedTools`) -`tools` and `disallowedTools` in agent frontmatter **have no effect in -`--agent` sessions**. They only work when the agent runs as a subagent -spawned via the Agent tool. +`tools` and `disallowedTools` in agent frontmatter ~~**have no effect in +`--agent` sessions**~~ see note. They only work when the agent runs as +a subagent spawned via the Agent tool. ### `--agent` sessions: `tools` neither restricts nor grants @@ -121,3 +129,9 @@ See [HOW_TO.md](HOW_TO.md). - **Claude CLI version:** 2.1.118 - **Date:** 2026-04-23 - **OS:** Linux 6.19.11-200.fc43.x86_64 (Fedora 43) + +> **Note (2026-07):** v2.1.119 was released on 2026-04-23 23:24 UTC — +> 21 hours after this experiment concluded. That release changed `tools` +> and `disallowedTools` enforcement in `--agent`/`--print` sessions. +> Results in section 1 are accurate for v2.1.118 but no longer reflect +> current behavior.