1
00:00:00,079 --> 00:00:03,179
Brought to you by Jellypod AI, picture
this scenario.

2
00:00:03,259 --> 00:00:06,739
You think you are being clever setting up
custom permissions in Claude Code.

3
00:00:07,379 --> 00:00:10,699
You put in an allow rule like Bash git
wildcard main, right?

4
00:00:11,359 --> 00:00:15,239
Because you just want to let it run git
checkout main or git pull main without

5
00:00:15,259 --> 00:00:16,680
nagging you every single time.

6
00:00:16,887 --> 00:00:18,667
Yeah, nah, sounds dead simple, mate.

7
00:00:18,867 --> 00:00:22,867
I, I, I reckon half the devs out there
have written a rule just like that to save

8
00:00:22,907 --> 00:00:24,047
two seconds of typing.

9
00:00:24,801 --> 00:00:25,201
Right!

10
00:00:25,441 --> 00:00:30,401
But here is the massive security loophole
in version 2.1.246.

11
00:00:31,081 --> 00:00:35,621
If that wildcard sits before the
subcommand, you just handed the model an open door

12
00:00:35,661 --> 00:00:38,641
to run arbitrary code without any prompt
at all.

13
00:00:38,807 --> 00:00:41,807
mate that is proper sketchy.

14
00:00:42,507 --> 00:00:47,928
See, the way wildcards work in Claude Code
allow rules, it matches raw text string

15
00:00:48,008 --> 00:00:48,508
patterns.

16
00:00:48,968 --> 00:00:53,187
So if you write git wildcard main,
intended for git checkout main,

17
00:00:53,687 --> 00:00:56,987
it also blindly matches flags placed
before the subcommand!

18
00:00:57,487 --> 00:01:03,947
Like, um, git exec path equals slash tmp
slash bin main, or

19
00:01:04,367 --> 00:01:10,728
git c core dot pager equals cat slash etc
slash passwd main.

20
00:01:11,037 --> 00:01:14,418
Wait, so because the wildcard is loose
before the subcommand,

21
00:01:14,477 --> 00:01:19,117
an attacker or a hallucinated command
could slip executable flags right into that

22
00:01:19,137 --> 00:01:19,438
gap?

23
00:01:19,917 --> 00:01:20,557
Spot on.

24
00:01:20,690 --> 00:01:25,197
It just evaluates that the string starts
with git, has something in the middle,

25
00:01:25,237 --> 00:01:26,637
and ends with main.

26
00:01:26,877 --> 00:01:31,197
Boom, auto approved, bypasses all your
safety checks.

27
00:01:31,261 --> 00:01:37,437
That is why Anthropic just added a big
bright startup warning in 2.1.246 whenever it

28
00:01:37,487 --> 00:01:41,357
detects a wildcard sitting before a
subcommand in your Bash rules.

29
00:01:41,375 --> 00:01:42,255
So how do we fix it?

30
00:01:42,383 --> 00:01:45,535
What is the right way to re architect
these rules?

31
00:01:45,661 --> 00:01:46,421
Super straightforward.

32
00:01:46,841 --> 00:01:51,361
You replace those loose prefixed wildcards
with explicit subcommand patterns.

33
00:01:51,921 --> 00:01:56,061
Instead of git wildcard main, you write
Bash git checkout wildcard,

34
00:01:56,321 --> 00:01:57,962
or Bash git pull main.

35
00:01:58,621 --> 00:02:03,001
Keep the wildcard after the explicit
action word so flags cannot hide in front of

36
00:02:03,042 --> 00:02:03,181
it.

37
00:02:03,841 --> 00:02:07,941
And look, if you hate hand editing dot
claude slash settings dot json,

38
00:02:08,281 --> 00:02:10,581
you can just pop open slash permissions in
the terminal.

39
00:02:11,181 --> 00:02:15,581
They added a handy Auto mode tab right
inside the interface so you can audit all

40
00:02:15,621 --> 00:02:17,042
your classifier rules visually.

41
00:02:17,747 --> 00:02:22,747
Lachlan, this whole thing feels like
classic early career shell scripting traps.

42
00:02:22,807 --> 00:02:26,367
Didn't you once tell me about a wild
deployment script blunder back in Newcastle?

43
00:02:27,816 --> 00:02:29,756
Oh mate, do not remind me.

44
00:02:30,656 --> 00:02:35,476
I was twenty one, working out of my shed
in Newcastle, writing automated deploy

45
00:02:35,576 --> 00:02:36,797
scripts for an indie client.

46
00:02:37,576 --> 00:02:42,837
I put a lazy rm rf wildcard build path in
a hook, thinking it would only ever clear

47
00:02:42,876 --> 00:02:43,956
the local dist folder.

48
00:02:44,796 --> 00:02:48,456
Turned out a path variable resolved to
empty on one bad midnight update,

49
00:02:48,936 --> 00:02:52,296
and that bloody wildcard wiped out half
the staging root directory!

50
00:02:54,156 --> 00:02:55,976
I had to own up to the client at 2 AM.

51
00:02:56,716 --> 00:03:01,576
Taught me to never, ever leave loose
wildcards anywhere near command execution.

52
00:03:01,625 --> 00:03:04,105
Man, tough lesson, but classic.

53
00:03:04,242 --> 00:03:10,505
Before we wrap, there are two really nice
quality of life tweaks in 2.1.246 too,

54
00:03:10,532 --> 00:03:10,825
right?

55
00:03:10,973 --> 00:03:11,173
Yeah!

56
00:03:11,412 --> 00:03:12,352
Small but brilliant.

57
00:03:12,992 --> 00:03:16,753
End of turn duration lines now append
exact completion timestamps,

58
00:03:17,112 --> 00:03:20,793
like Sautéed for 23s, done 6:05 PM.

59
00:03:21,772 --> 00:03:25,232
Super handy when you drop a long running
task in the background and want to know

60
00:03:25,253 --> 00:03:27,492
when it finished without digging through
terminal logs.

61
00:03:27,625 --> 00:03:30,265
And terminal diffs finally stop crashing!

62
00:03:30,425 --> 00:03:35,465
If a tool output produces a massive single
line like a huge base 64 blob,

63
00:03:35,513 --> 00:03:39,625
diff rendering now auto truncates it
instead of freezing your whole terminal window.

64
00:03:39,684 --> 00:03:42,504
That alone saves so many forced terminal
restarts.

65
00:03:43,184 --> 00:03:47,824
Lock down those git wildcards, check your
permissions tab, and enjoy the clean logs!

