perf/session-latency.md section 7, tier E1, counts 17 blocked or denied tool_result records across the session's 11 transcripts: block-hook-bypass on Bash 15 times, on PowerShell once, and one "Permission for this action was denied". The blocked calls consumed 48.2 s; priced with a forced retry turn at the 3.8 s median model latency, that is 113.5 agent-seconds (section 8B), a lower bound: it omits generation and the replacement tool call.
Two reconciliations. Section 5 reports PreToolUse:Bash block-hook-bypass at 9 against section 7's 15: different populations (hook_system_message attachments versus blocked tool_result records), unstated in the file. This counter is the section 7 population. And the 17 are attributed by message string, not guard name, so the per-guard split is not established: the guardrails evidence file's claim that all 17 were block-hook-bypass contradicts its own worked examples, a ps-unparsable-launcher block and a --force-with-lease block belonging to other guards.
perf/snapshot-baseline.md section 3 corroborates the invocation-form cost: 4 attempts at render-and-lint.ps1 in the main transcript produced exactly 1 real execution: a guard block on the PowerShell form (0.5 s), an Import-Module failure from a -File invocation (2.8 s), a call that printed parameter help and never ran (2.0 s), then the working form at 40.6 s. Three of four were shape errors, not policy violations.
Cheapest fix: have guard rejection messages carry the exact allowed command form, not just the rule that fired, turning a retry loop into one correction. Second: document the working shape for a repo script under pwsh, pwsh -NoProfile -NonInteractive -WorkingDirectory <dir> -Command "<script>; exit $LASTEXITCODE", in the guardrails README next to the launcher rule. The companion issues on the wsl bypass and the /tmp false positives remove separate slices of this count.
Maintainer note: the "PowerShell costs about 5x Bash" line that circulates with this one is tier E4. perf/target-ranking.md rank 7 ran the toolUseID to tool_use.name join: all 9 measured run-guards fires are Bash, zero PowerShell samples in the corpus. No measurement on either side.
Verification: blocked or denied tool_result records per session, baseline 17, from the section 7 population. Also useful: attempts per successful render-and-lint.ps1 execution, currently 4 to 1.
🤖 Generated with Claude Code
https://claude.ai/code/session_01F7GFS5autRMSaea6kSoXzx
perf/session-latency.mdsection 7, tier E1, counts 17 blocked or deniedtool_resultrecords across the session's 11 transcripts: block-hook-bypass on Bash 15 times, on PowerShell once, and one "Permission for this action was denied". The blocked calls consumed 48.2 s; priced with a forced retry turn at the 3.8 s median model latency, that is 113.5 agent-seconds (section 8B), a lower bound: it omits generation and the replacement tool call.Two reconciliations. Section 5 reports
PreToolUse:Bashblock-hook-bypass at 9 against section 7's 15: different populations (hook_system_messageattachments versus blockedtool_resultrecords), unstated in the file. This counter is the section 7 population. And the 17 are attributed by message string, not guard name, so the per-guard split is not established: the guardrails evidence file's claim that all 17 were block-hook-bypass contradicts its own worked examples, aps-unparsable-launcherblock and a--force-with-leaseblock belonging to other guards.perf/snapshot-baseline.mdsection 3 corroborates the invocation-form cost: 4 attempts atrender-and-lint.ps1in the main transcript produced exactly 1 real execution: a guard block on the PowerShell form (0.5 s), anImport-Modulefailure from a-Fileinvocation (2.8 s), a call that printed parameter help and never ran (2.0 s), then the working form at 40.6 s. Three of four were shape errors, not policy violations.Cheapest fix: have guard rejection messages carry the exact allowed command form, not just the rule that fired, turning a retry loop into one correction. Second: document the working shape for a repo script under pwsh,
pwsh -NoProfile -NonInteractive -WorkingDirectory <dir> -Command "<script>; exit $LASTEXITCODE", in the guardrails README next to the launcher rule. The companion issues on thewslbypass and the/tmpfalse positives remove separate slices of this count.Maintainer note: the "PowerShell costs about 5x Bash" line that circulates with this one is tier E4.
perf/target-ranking.mdrank 7 ran thetoolUseIDtotool_use.namejoin: all 9 measured run-guards fires are Bash, zero PowerShell samples in the corpus. No measurement on either side.Verification: blocked or denied
tool_resultrecords per session, baseline 17, from the section 7 population. Also useful: attempts per successfulrender-and-lint.ps1execution, currently 4 to 1.🤖 Generated with Claude Code
https://claude.ai/code/session_01F7GFS5autRMSaea6kSoXzx