Skip to content

disk-hygiene: prove the apply --execute guard holds in every permission mode #5609

Description

@kyle-sexton

Problem

The disk-hygiene destructive guard gates hygiene.py apply --execute with a PreToolUse hook that returns permissionDecision: "ask". Whether that ask holds is documented for some permission modes and not others:

  • Probed and held (2026-09-30, Claude Code 2.1.285, Linux/WSL2, Bash tool): headless default mode denied the call; --bg default mode parked at the prompt; headless --permission-mode bypassPermissions listed the call in permission_denials and the target survived (PR feat(disk-hygiene): add model-invocable read-only audit skill #5590, comments 5916629407 and the probe table in its body).
  • Not probed: an interactive session in bypassPermissions, auto mode, and the Windows PowerShell tool.
  • The official docs do not name hook ask under bypassPermissions. The /permission-modes "Actions no mode auto-approves" list names ask rules, not hook ask. Upstream [BUG] Bypass permission mode resets after a PreToolUse hook returns "ask" anthropics/claude-code#37420 (closed, 2026-03) reports the prompt still appears interactively; #79356 (2.1.215, Windows, PowerShell tool, closed stale) reports a hook ask not enforced. Research record: .work/hook-ask-bypass-permissions/RESEARCH.md (memory tier, not committed).

So the only gate on the irreversible lane rests on behavior that is undocumented for two of the modes a session can be in.

Acceptance criteria

  1. Probe the guard's ask on apply --execute in: an interactive bypassPermissions session, auto mode, and the PowerShell tool on a Windows fleet host. Record mode, version, tool, result and the target listing on this issue.
  2. Decide whether apply --execute also needs a gate that does not depend on the permission mode (an engine-side confirmation, or a hook deny in modes where ask cannot reach a person), and implement the chosen one with tests, or record why not.
  3. Add a four-part verification record (Claim, Basis, As of, Recheck) for the hook-ask-under-bypass behavior to the disk-hygiene safety-model reference, with a recheck trigger on any Claude Code changelog entry that names PreToolUse ask or bypassPermissions.

Related

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-humanHuman-in-the-loop required; autonomous sessions must not resolve items carrying this.priority: mediumReal value, no hard deadline; normal backlog flow.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions