---
title: 'In the News: October 4, 2026 (Extra)'
description: 'Claude Code 2.1.288 and 2.1.289 close several gaps in Bash deny and ask rules under sandbox auto-allow, and in hooks that were silently skipped.'
canonical_url: 'https://darkfactory.dev/news/2026-10-04-extra'
markdown_url: 'https://darkfactory.dev/news/2026-10-04-extra.md'
collection: news
date_published: '2026-10-04T10:20:00-04:00'
date_modified: '2026-10-04T10:20:00-04:00'
---

# In the News: October 4, 2026 (Extra)


Two Claude Code releases from October 2 and 3 fix a run of cases where permission rules and hooks did not hold. If you lean on Bash deny and ask rules, or on PreToolUse hooks, to keep an unattended agent in bounds, the entries are worth reading before you assume your current version enforced them.

## 1. Claude Code 2.1.288 and 2.1.289 fix deny and ask rules that were skipped under sandbox auto-allow

**[Claude Code changelog](https://code.claude.com/docs/en/changelog)** · Anthropic · Versions 2.1.288 (October 2, 2026) and 2.1.289 (October 3, 2026)

The changelog lists several permission fixes. One says a "Bash deny or ask rule" was "skipped under sandbox auto-allow when a bare variable assignment came before the command." Another covers deny and ask rules "missing a command behind an environment variable prefix with an expanded value (e.g. `TZ="$HOME" rm -rf build`) when the sandbox auto-allows commands." A third says a deny or ask rule on a nested part of a compound shell command did not hold "over a user-installed mod's approval on managed machines."

Two more concern guardrails that failed open. A dangerous `rm`, such as one on `/` or the home directory, inside a `bash -c` or `sh -c` script ran "without a prompt in bypassPermissions mode or under a shell allow rule." And PreToolUse and PermissionRequest hooks were skipped "when matching them failed or the tool's input could not be serialized to JSON"; the call is now blocked. 2.1.289 also fixes `Read` deny rules not applying to files changed or selected in the IDE through a symlink.

The changelog describes these as fixes. It does not say whether any were exploited or how many installs were affected, and this item rests on the changelog text alone.

**Why it matters:** The affected paths are the ones people use to let an agent run without a human approving each command: sandbox auto-allow, allow rules, and bypassPermissions. If your setup depends on a deny rule or a hook to stop a destructive command, these entries describe command shapes where it did not apply, so upgrading is the first step. They are also a reason to keep a second limit under the rules, such as a sandbox or a scoped working directory.

---

## Also this cycle

- **[Agents Don't Need Memory. They Need Documentation.](https://liao.gg/blog/agents-dont-need-memory)** · Kevin Liao, Aerovato Research · liao.gg, October 3, 2026 · Argues that memory plugins reduce to retrieval over past conversations and that a structured Markdown workspace the agent reads before work and updates after it is the better design. The evidence is the author's own year of use of his open-source Operator Memory plugin; no measurements are reported, so treat it as a practitioner's claim.
