You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The disk-hygiene destructive guard gates hygiene.py apply --execute with a PreToolUse hook that returns permissionDecision: "ask". Whether that ask holds is documented for some permission modes and not others:
Probed and held (2026-09-30, Claude Code 2.1.285, Linux/WSL2, Bash tool): headless default mode denied the call; --bg default mode parked at the prompt; headless --permission-mode bypassPermissions listed the call in permission_denials and the target survived (PR feat(disk-hygiene): add model-invocable read-only audit skill #5590, comments 5916629407 and the probe table in its body).
Not probed: an interactive session in bypassPermissions, auto mode, and the Windows PowerShell tool.
The official docs do not name hook ask under bypassPermissions. The /permission-modes "Actions no mode auto-approves" list names ask rules, not hook ask. Upstream [BUG] Bypass permission mode resets after a PreToolUse hook returns "ask" anthropics/claude-code#37420 (closed, 2026-03) reports the prompt still appears interactively; #79356 (2.1.215, Windows, PowerShell tool, closed stale) reports a hook ask not enforced. Research record: .work/hook-ask-bypass-permissions/RESEARCH.md (memory tier, not committed).
So the only gate on the irreversible lane rests on behavior that is undocumented for two of the modes a session can be in.
Acceptance criteria
Probe the guard's ask on apply --execute in: an interactive bypassPermissions session, auto mode, and the PowerShell tool on a Windows fleet host. Record mode, version, tool, result and the target listing on this issue.
Decide whether apply --execute also needs a gate that does not depend on the permission mode (an engine-side confirmation, or a hook deny in modes where ask cannot reach a person), and implement the chosen one with tests, or record why not.
Add a four-part verification record (Claim, Basis, As of, Recheck) for the hook-ask-under-bypass behavior to the disk-hygiene safety-model reference, with a recheck trigger on any Claude Code changelog entry that names PreToolUse ask or bypassPermissions.
Problem
The disk-hygiene destructive guard gates
hygiene.py apply --executewith a PreToolUse hook that returnspermissionDecision: "ask". Whether thataskholds is documented for some permission modes and not others:--bgdefault mode parked at the prompt; headless--permission-mode bypassPermissionslisted the call inpermission_denialsand the target survived (PR feat(disk-hygiene): add model-invocable read-only audit skill #5590, comments 5916629407 and the probe table in its body).bypassPermissions, auto mode, and the Windows PowerShell tool.askunderbypassPermissions. The/permission-modes"Actions no mode auto-approves" list names ask rules, not hookask. Upstream [BUG] Bypass permission mode resets after a PreToolUse hook returns "ask" anthropics/claude-code#37420 (closed, 2026-03) reports the prompt still appears interactively; #79356 (2.1.215, Windows, PowerShell tool, closed stale) reports a hookasknot enforced. Research record:.work/hook-ask-bypass-permissions/RESEARCH.md(memory tier, not committed).So the only gate on the irreversible lane rests on behavior that is undocumented for two of the modes a session can be in.
Acceptance criteria
askonapply --executein: an interactivebypassPermissionssession, auto mode, and the PowerShell tool on a Windows fleet host. Record mode, version, tool, result and the target listing on this issue.apply --executealso needs a gate that does not depend on the permission mode (an engine-side confirmation, or a hookdenyin modes whereaskcannot reach a person), and implement the chosen one with tests, or record why not.ask-under-bypass behavior to the disk-hygiene safety-model reference, with a recheck trigger on any Claude Code changelog entry that names PreToolUseaskorbypassPermissions.Related