github kenryu42/cc-safety-net v2.4.12

5 hours ago

This release makes a refused working directory explain itself instead of reporting a generic internal failure, and removes a group of false denials that hit agents working in a temporary scratch directory.

Highlights

  • A tool call refused because of its working directory now says which directory and why, and whether to restart the session or pick another directory, instead of the generic "CC Safety Net failed closed" message. (#157)
  • Commands that build and use a scratch directory under the temp root — naming a path in a shell variable, cd-ing into it, creating it with mkdir -p, or running find . -delete inside it — are no longer denied. (#158, #160, #161)

Changed

  • Changed the denial text checkCommand returns for a working directory it cannot use: it now names the specific problem rather than the generic failed-closed reason. (#157)
  • Moved the refused path from the Segment: line to a Working directory: line in the denial message, and recorded it as the audit entry's cwd. (#157)

Fixed

  • Fixed working-directory denials across all supported hosts — Claude Code, Codex, Copilot CLI, Gemini CLI, Kimi, Hermes, Cursor, Grok Build, Antigravity, Pi, OpenClaw, Amp and OpenCode — so a session directory that no longer exists asks the user to restart the session, and a per-call directory that is missing or outside the workspace asks for a different directory. (#157)
  • Fixed Antigravity refusing a workspace directory whose name begins with two dots, such as ..cache. (#157)
  • Fixed a shell script being refused as unverifiable when its path came from a literal shell assignment, as in S=/tmp/scratch; bash $S/build.sh. The same expansion now applies to git -C, git worktree remove, and the file a cat or tee heredoc writes. (#158)
  • Fixed an && or || outcome being lost across a pipeline, so A && B | C && D no longer analyzes D as if A had failed. (#158)
  • Fixed find . -delete being blocked after a cd, by judging the . starting point as the directory the cd entered. Deleting from a directory that contains the workspace, or from a temp root itself, stays blocked. (#160)
  • Fixed a later line being analyzed in the old directory after a successful cd, so cd X && A followed by B now evaluates B in X. A cd whose target is missing, dynamic, a regular file, or starts with ~ still leaves the directory unknown. (#160)
  • Fixed a cd into a directory an earlier mkdir or mkdir -p created in the same command being treated as a missing path. A mkdir that may have failed, or one without -p whose parent is missing, records nothing. (#161)

Don't miss a new cc-safety-net release

NewReleases is sending notifications on new releases.