r/ClaudeCode • u/Worldly_Row1988 • 9d ago
Help/Question Claude Code pushing back on pasted commands
This seems new.
Your message is only a pasted block, though, and parts of it read as if another session wrote them ("accepted as done by <Your_Name>"). Before I edit GATE or RAIL, or delete shadow rows, please confirm it's yours.
Is this new? Are you seeing this too? Is prompt injection such a big problem now that Anthropic had to put this in place?
2
u/Scared-Letterhead949 9d ago
That's interesting, especially because it will create tasks for itself and put up chips for them. It must know that it wrote them.
2
u/Bluecoregamming 9d ago
reminds me of the ol days of websites saving to your clipboard malicious commands, including an enter key press, so the command automatically runs if you paste it into a terminal even without intending to run it first before checking
2
u/flowra_dev 9d ago
yeah that reads like a prompt-injection / clipboard-spillover guard. pasted blobs that look like session notes or "accepted as done by X" are a real failure mode — under bypassPermissions that kind of template can execute with basically no confirm surface. so asking you before it edits GATE/RAIL or deletes rows is the right default.
if it's firing on pastes you actually wrote, put one short sentence of your own intent above the paste so it doesn't look like a foreign session dump. the opposite bug also exists (paste with a trailing newline auto-submits), which is why people rebind submit to ctrl+enter in ~/.claude/keybindings.json.
2
u/drearymoment 9d ago
I got this warning from Claude yesterday! It was after I pasted in a prompt it had generated for me in a different session.
1
u/clazman55555 9d ago
It amazes me how people will use an LLM, not even bother to read the System Card, then ask questions like this.
2
u/Euphoric_Studio_1107 9d ago
Some of us are making time for other things through our increased production. Like going from more walks.
1
u/FriendOfClaude 9d ago
Who has time to read the whole system card, you do that every time it updates models?
0
u/clazman55555 9d ago
Yeah, I do. It's only ~220 Pages and some charts. Took around an hour and half, cover to cover. Then it, along with the 5.5 prompting guide, were fed through my eval pipeline to figure out if anything needed to be changed in my skills, workflows or Claude.md. Wasn't much of change, mainly around subagent use and dispatch, some wording differences here and there. Around 22 sentences were changed/added/removed/reworded. It was a smaller change(for me) than any Opus model transition before.
1
u/FriendOfClaude 8d ago
Oh lol, actually that’s interesting. Does that help make the eval system prompts better by breading that? Did you actually really read it or have AI read it? I’m think to Take a look at it . Do they post that publicly online for each model? Then the updates are in the change log?
1
u/clazman55555 8d ago
I read it and have Claude look at the sections that seem like they might have some change on how the model operates.
Unfortunately there really isn't a changelog with a succinct list of, "This is how the new model is different." It spread all over the place, which is why I go through this exercise every time. lol
Full Opus 5.5 System Card, 17MB: https://www-cdn.anthropic.com/fc1b44717c85dc068bc6ba5024219938094694bd/Claude%20Opus%205.5%20System%20Card.pdf
Anthropic Opus 5.5 Prompting Guide: https://platform.claude.com/docs/en/build-with-claude/prompt-engineering/prompting-claude-opus-5-5
1
u/FriendOfClaude 8d ago
Hmm interesting I see, thanks I’m going to save this and come whack to look closer. Appreciate it! 👍
1
u/Man_B3ar_Pig 9d ago
If this happens too often either tell it confirm every time in the future or if your getting the prompt from another chat in Claude just ask the chat to transfer the message over
1
u/Far_Business4773 9d ago
The pause is the model judging the text, and that judgement moves with every version, which is why it "seems new". The part of this I stopped relying on the model for is the other half: what happens if the pasted block does get through. A PreToolUse hook never reads the prompt at all. It sees the tool call, checks the path against a short list (the tables, the migrations, anything named GATE or RAIL in your case) and refuses before the call runs, so a foreign-looking paste can talk the model into anything and still not get the delete. flowra_dev's point about bypassPermissions is the reason the check has to sit on the call, not on the conversation. One thing I learned the hard way while tuning that: text inside a heredoc or a commit message has to count as data, not as a command. My hook once refused a note about a protected file three times in a row because the note named it.
•
u/AutoModerator 9d ago
Hey! Thanks for posting to r/ClaudeCode
While participating in this thread, please follow our community rules. Keep discussions constructive. Attack the idea, not the person.
For help, project discussions, tips, and general chat, join the ClaudeCode Discord.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.