This release makes a refused working directory explain itself instead of reporting a generic internal failure, and removes a group of false denials that hit agents working in a temporary scratch directory.
Highlights
- A tool call refused because of its working directory now says which directory and why, and whether to restart the session or pick another directory, instead of the generic "CC Safety Net failed closed" message. (#157)
- Commands that build and use a scratch directory under the temp root — naming a path in a shell variable,
cd-ing into it, creating it withmkdir -p, or runningfind . -deleteinside it — are no longer denied. (#158, #160, #161)
Changed
- Changed the denial text
checkCommandreturns for a working directory it cannot use: it now names the specific problem rather than the generic failed-closed reason. (#157) - Moved the refused path from the
Segment:line to aWorking directory:line in the denial message, and recorded it as the audit entry'scwd. (#157)
Fixed
- Fixed working-directory denials across all supported hosts — Claude Code, Codex, Copilot CLI, Gemini CLI, Kimi, Hermes, Cursor, Grok Build, Antigravity, Pi, OpenClaw, Amp and OpenCode — so a session directory that no longer exists asks the user to restart the session, and a per-call directory that is missing or outside the workspace asks for a different directory. (#157)
- Fixed Antigravity refusing a workspace directory whose name begins with two dots, such as
..cache. (#157) - Fixed a shell script being refused as unverifiable when its path came from a literal shell assignment, as in
S=/tmp/scratch; bash $S/build.sh. The same expansion now applies togit -C,git worktree remove, and the file acatorteeheredoc writes. (#158) - Fixed an
&&or||outcome being lost across a pipeline, soA && B | C && Dno longer analyzesDas ifAhad failed. (#158) - Fixed
find . -deletebeing blocked after acd, by judging the.starting point as the directory thecdentered. Deleting from a directory that contains the workspace, or from a temp root itself, stays blocked. (#160) - Fixed a later line being analyzed in the old directory after a successful
cd, socd X && Afollowed byBnow evaluatesBinX. Acdwhose target is missing, dynamic, a regular file, or starts with~still leaves the directory unknown. (#160) - Fixed a
cdinto a directory an earliermkdirormkdir -pcreated in the same command being treated as a missing path. Amkdirthat may have failed, or one without-pwhose parent is missing, records nothing. (#161)