Repository navigation
Patch release that shows an operator the shell command a Claude Code prompt asks to run, in the desktop application and in the web gateway: since v0.8.18 the prompt had an honest title and no command, which had to be read in the terminal. The command is redacted line by line, keeping what follows a masked value, bounded, and never sent to a viewer. A shell-command prompt no longer carries a tool-call badge, which could have carried the rest of the command to viewers, and the modal's terminal tail loses its escape sequences. The command is read from the agent's screen and the redaction knows common credential forms only, so check it against the terminal before you allow anything.
Added
-
The decision modal shows the command a prompt asks about. For a shell command Claude Code asks to run, the title was honest since v0.8.18 but the command itself reached no screen: the prompt's summary is a constant, and the command the adapter read was kept in the event and shown nowhere. The core's prompt view now carries it, in the desktop application and in the web gateway, and the modal draws it in its own block under the summary. Only the Claude Code shell-command prompt has one: the generic adapter's
command, a quoted fragment of the question such as a file name or the wordyes, is read by the policy and is not shown. Each line is redacted as the journal redacts values and keeps the text after a masked value, soTOKEN=x curl ... | shreadsTOKEN=[REDACTED] curl ... | shrather than stopping at the mask; the line breaks are kept, and the command is cut at eight lines of 200 characters, with a mark where it was cut. A bidi override or a zero-width character shows as a replacement character instead of reordering or hiding what is read. A prompt that is a secret (marked sensitive, or a credential) carries none. The redaction knows common credential forms only: a flag whose argument is the secret (mysql -pSECRET), a password piped to a command and a bare key with no known prefix are shown. The command is read from the agent's screen by rules that fit the layouts seen, so it is advisory: check it against the terminal before you allow anything. The TUI does not show it. The command is never written to the audit journal. -
A viewer is never sent the command. The gateway removes it from every frame and every state a viewer receives, as it removes the host's version and the journal's path. With the terminals shown, a viewer can still read the command where the agent printed it;
--viewer-terminals hiddencloses that. An operator's copy is left as it was.
Fixed
-
A shell command Claude Code asked about could become a tool-call badge that every client was shown. The badge is read from the same screen text as the prompt, so a command that names
mcp__a__bfollowed byhost=...produced a badge whose parameters held the rest of the command, redacted but otherwise as the agent typed it, in the prompt card of every client, viewers included. A Claude Code shell-command prompt asks about a command, not a tool call, and no longer carries a badge. A genuine MCP tool-call prompt keeps its badge, with its redacted, bounded parameters, for viewers too, as the web gateway documents. -
The gateway sent the unmasked frame to any role but a viewer. There are only two roles, so nothing reached a client it should not have; the choice now fails closed, and an operator alone is sent the frame with the command in it.
-
The last lines of output in the decision modal were the terminal's raw text. For a Claude Code shell command they carried colour codes, cursor movements and window-title strings, which the modal printed as stray characters or let split a word into two. They are now taken out before the lines are cut and redacted, so a secret that an escape sequence split in two is one text again when it is redacted. A cursor move to the right becomes spaces, since Claude Code spaces its words that way; the other moves are dropped, so a screen the agent painted by positioning the cursor reads as the text it wrote, not as the grid a terminal shows. A line is cut at a character, not through an emoji, and the redaction is run on at most 1,024 characters of a line: the URL pattern is quadratic in a long run of letters and digits, and 256 KiB of them an agent prints would have frozen the window.
Full commit list: v0.8.18...v0.8.19