Added
- CC-SET-012: Invalid sandbox.credentials Setting (closes #1078). Claude Code v2.1.187 added
sandbox.credentialsto block sandboxed commands from reading credential files and secret environment variables. New MEDIUMclaude-settingsrule validates the documentedsandbox.credentials.files[]andsandbox.credentials.envVars[]shapes: file entries require a non-empty stringpathandmode: "deny", env var entries require a non-empty stringnameandmode: "deny", and no other mode is documented. Validated acrosssettings.json,settings.local.json, andmanaged-settings.json. Rule count 429 -> 430.
Changed
- Tool baseline: bumped
claude-codev2.1.186->v2.1.187after release-note/source triage. The other v2.1.187 changes are model restrictions, UI behavior, CLI flag/help, runtime bug fixes, and remote-session behavior outside agnix's validated config surfaces. NoToolVersionsorSpecRevisionschange required..github/tool-release-baselines.json,knowledge-base/RESEARCH-TRACKING.md, rule metadata, and generated rule docs were updated.