1
00:00:00,079 --> 00:00:00,799
So, picture this.

2
00:00:01,259 --> 00:00:03,899
You set an AI coding agent loose in auto
mode, right?

3
00:00:04,559 --> 00:00:06,960
You tell it to fix a bug in your web app,
you grab a coffee,

4
00:00:07,399 --> 00:00:08,319
and while you're away...

5
00:00:09,079 --> 00:00:11,420
it starts reading files from your root
directory.

6
00:00:11,939 --> 00:00:14,759
Or grabbing your personal cloud keys from
somewhere else on disk.

7
00:00:15,472 --> 00:00:17,032
Yeah, nah, that is...

8
00:00:17,071 --> 00:00:18,231
that is terrifying, mate.

9
00:00:18,971 --> 00:00:23,371
Like leaving a tradesman to fix a leaky
tap in the bathroom and coming home to find

10
00:00:23,371 --> 00:00:25,212
him digging through your bedroom
nightstand.

11
00:00:25,912 --> 00:00:27,011
Exactly!

12
00:00:27,032 --> 00:00:31,192
And until version 2 point 1 point 257 of
Claude Code...

13
00:00:31,732 --> 00:00:33,292
brought to you by Jellypod AI...

14
00:00:34,031 --> 00:00:35,632
auto mode actually let that happen!

15
00:00:36,172 --> 00:00:39,172
It auto approved plain file reads anywhere
on your machine.

16
00:00:39,348 --> 00:00:40,107
Wait, seriously?

17
00:00:40,967 --> 00:00:42,007
So it didn't even...

18
00:00:43,167 --> 00:00:46,147
it didn't even ask if it wandered outside
the project folder?

19
00:00:46,333 --> 00:00:46,573
Nope!

20
00:00:46,717 --> 00:00:50,213
Auto mode's classifier was built to stop
big destructive stuff,

21
00:00:50,237 --> 00:00:52,813
like force pushing to main or dropping a
database.

22
00:00:52,933 --> 00:00:54,253
But reading a file?

23
00:00:54,360 --> 00:00:55,453
It just let it slide.

24
00:00:55,693 --> 00:01:00,093
So if an injected prompt inside a
dependency told Claude to go inspect a file in

25
00:01:00,133 --> 00:01:02,173
another directory, it would just do it.

26
00:01:03,026 --> 00:01:03,606
Crikey.

27
00:01:03,866 --> 00:01:06,746
That is a massive blind spot for prompt
injection, hey?

28
00:01:06,792 --> 00:01:07,592
Huge.

29
00:01:07,672 --> 00:01:13,912
But in version 2 point 1 point 257, they
added out of bounds read protection.

30
00:01:14,072 --> 00:01:20,152
The very first time Claude calls tools
like Read, Grep, or Glob on a path outside

31
00:01:20,184 --> 00:01:24,312
your active working directory, it halts
and gives you a one time prompt.

32
00:01:24,292 --> 00:01:25,332
Right, right, so...

33
00:01:25,359 --> 00:01:28,772
so it hits a boundary and goes, hey mate,
am I allowed out here?

34
00:01:28,792 --> 00:01:29,272
Right!

35
00:01:29,312 --> 00:01:33,912
And if you click Block from now on, it
writes a line to your settings file...

36
00:01:33,965 --> 00:01:38,632
permissions dot
blockReadsOutsideWorkingDirectories set to true.

37
00:01:38,625 --> 00:01:39,665
Ah, beautiful!

38
00:01:39,825 --> 00:01:44,545
And once that setting is locked in, it's a
standing block across all your sessions

39
00:01:44,585 --> 00:01:45,905
and permission modes, yeah?

40
00:01:45,917 --> 00:01:46,557
Exactly.

41
00:01:46,603 --> 00:01:49,437
Unless you explicitly bring that path into
scope.

42
00:01:49,453 --> 00:01:53,357
Like, if you actually need Claude to look
at a sibling project,

43
00:01:53,377 --> 00:01:56,797
you can just run slash add dir and give it
the folder path,

44
00:01:56,824 --> 00:01:59,757
or add it to your JSON settings under
additionalDirectories.

45
00:01:59,750 --> 00:02:01,910
Now, wait on, what about headless runs?

46
00:02:02,006 --> 00:02:06,310
Like when I run Claude in a CI CD pipeline
with the minus p flag,

47
00:02:06,390 --> 00:02:10,390
or when a background subagent is running
where no human can click a pop up?

48
00:02:10,887 --> 00:02:12,247
That is the crucial part.

49
00:02:12,767 --> 00:02:17,347
In non interactive runs, if it tries to
read outside the working directory and you

50
00:02:17,447 --> 00:02:21,307
haven't pre approved it in your user
settings file, it doesn't wait...

51
00:02:21,347 --> 00:02:23,128
it just blocks it strictly.

52
00:02:23,187 --> 00:02:28,128
So setting permissions dot
blockReadsOutsideWorkingDirectories in your user config

53
00:02:28,187 --> 00:02:30,507
is basically mandatory for CI stability.

54
00:02:30,542 --> 00:02:31,582
That makes total sense.

55
00:02:31,692 --> 00:02:35,662
Prevent your automated builds from hanging
or leaking secrets.

56
00:02:35,882 --> 00:02:40,542
Now, didn't they also tighten up cloud
metadata endpoints in the same release?

57
00:02:40,542 --> 00:02:41,182
Oh yeah!

58
00:02:41,294 --> 00:02:43,502
They added Containment Escape rules.

59
00:02:43,630 --> 00:02:47,742
Auto mode used to be a little too trusting
if a malicious package tried to reach out

60
00:02:47,769 --> 00:02:50,222
to local cloud metadata services...

61
00:02:50,254 --> 00:02:56,222
like the AWS endpoint at 169 dot 254 dot
169 dot 254.

62
00:02:56,208 --> 00:02:59,648
Ah, the classic IMDS credential fetch
trick!

63
00:02:59,828 --> 00:03:03,008
Sneaky buggers try to grab instance role
tokens.

64
00:03:03,000 --> 00:03:03,480
Yep!

65
00:03:03,620 --> 00:03:08,280
Now, any request targeting cloud metadata,
or attempting egress evasion,

66
00:03:08,333 --> 00:03:11,480
or trying to reach across tenant
boundaries is blocked cold.

67
00:03:11,640 --> 00:03:13,960
It won't auto approve those anymore,
period.

68
00:03:14,557 --> 00:03:19,837
Man, that gives me a lot more peace of
mind running auto mode while I go make a tea.

69
00:03:21,697 --> 00:03:25,697
Now, speaking of minor developer wins,
didn't they touch up the terminal controls

70
00:03:25,737 --> 00:03:26,298
recently too?

71
00:03:27,434 --> 00:03:30,234
Oh, version 2 point 1 point 261!

72
00:03:30,554 --> 00:03:30,934
Yes!

73
00:03:31,574 --> 00:03:34,394
If you spend all day typing in the
terminal, you'll love this.

74
00:03:34,894 --> 00:03:38,234
Word editing shortcuts now strictly match
native Bash behavior.

75
00:03:38,292 --> 00:03:41,972
Oh, tell me Ctrl W actually deletes back
to whitespace now!

76
00:03:41,958 --> 00:03:42,518
It does!

77
00:03:42,582 --> 00:03:47,798
Ctrl W deletes back to whitespace, and Alt
F and Alt D jump or delete to word

78
00:03:47,849 --> 00:03:51,158
boundaries cleanly, using punctuation as
delimiters.

79
00:03:51,238 --> 00:03:56,038
They completely retired the old
keybindingFlavor setting because standard Bash style

80
00:03:56,091 --> 00:03:57,638
is now the default everywhere.

81
00:03:57,625 --> 00:03:58,345
Good riddance!

82
00:03:58,448 --> 00:04:02,585
Trying to edit a long prompt with weird
keybindings felt like steering a shopping

83
00:04:02,625 --> 00:04:03,865
trolley with a broken wheel.

84
00:04:03,977 --> 00:04:05,866
What about proxy diagnostics?

85
00:04:06,025 --> 00:04:09,785
I know a few enterprise dev mates who get
stuck behind corporate firewalls.

86
00:04:09,792 --> 00:04:14,352
Right, so in 2 point 1 point 261, when
your org policy fails to load,

87
00:04:14,422 --> 00:04:18,192
running status or claude doctor gives you
the exact reason.

88
00:04:18,288 --> 00:04:22,752
Like if a corporate proxy stripped an
endpoint header, it actually tells you instead

89
00:04:22,779 --> 00:04:24,272
of just failing silently.

90
00:04:24,292 --> 00:04:26,372
And timestamps in session transcripts!

91
00:04:26,512 --> 00:04:31,332
Did I see 2 point 1 point 257 added custom
time formats?

92
00:04:31,333 --> 00:04:31,893
It did!

93
00:04:32,033 --> 00:04:35,413
You can set timeFormat and timeZone in
settings for 12 hour,

94
00:04:35,493 --> 00:04:39,573
24 hour UTC, or full strftime patterns on
your transcript clocks.

95
00:04:39,742 --> 00:04:40,362
Fantastic.

96
00:04:40,462 --> 00:04:45,182
So tighter security, better terminal
muscle memory, and clearer logs.

97
00:04:45,242 --> 00:04:46,882
Not a bad set of updates at all, mate.

98
00:04:47,333 --> 00:04:48,053
Not at all.

99
00:04:48,181 --> 00:04:51,733
Lock down those working directories, and
let the agent do the work!

