Urgent.News

What's breaking now, across thousands of outlets.

AI

Claude Code read a file listed in .claudeignore 12 of 12 times; a Read deny rule blocked every read except grep -r

A .claudeignore entry changed nothing in Claude Code 2.1.289: the fake secret it listed came back in 12 of 12 attempts across Read, cat , grep -r , the Grep tool and an @-mention. A Read(./secret.txt) deny rule blocked all of those except grep -r , which printed the secret in 2 of 2 runs; adding the file to .gitignore as well closed that gap too, but only while Claude Code's built-in grep was the…

The .claudeignore file in Claude Code 2.1.289 had no effect across 12 out of 12 attempts to read a file listed in it. The fake secret it contained was returned in every attempt, regardless of the tool used, such as Read, cat, grep -r, the Grep tool, or an @-mention. A Read(./secret.txt) deny rule blocked all attempts except grep -r, which successfully printed the secret in every trial.

Adding the file to .gitignore also closed the gap, but only when Claude Code's built-in grep was running. .claudeignore files are commonly found in starter repositories, blog posts, and the practices of users migrating from Cursor, a platform with its own .cursorignore feature. Claude Code's permissions page confirms that the file serves no purpose, answering half of the mystery.

The other half pertains to what keeps a file out, how it is blocked, and where each guard stops. To uncover these answers, we created four small git repositories, each with a single fake secret guarded in a different way. We ran Claude Code 40 times against each repository, checking every tool result and attachment for the secret's codeword.

All testing took place on 2026-10-05 between 16:25 and 16:33 UTC using Claude Code 2.1.289 and claude-opus-5-5 on macOS. Claude Code's permissions documentation states that .claudeignore files have no impact on Claude's file tools, such as Grep and Glob, or on @-mentions in prompts. However, the file is excluded from file discovery and search results, denied reads, and blocked in the Edit and Write tools.

This contradicts Claude's stated behavior, with the documentation suggesting that .claudeignore files should replace the deprecated ignorePatterns configuration. The changelog reveals that the grep -r gap, previously observed, has not been fixed in any of the 26 releases between 2.1.260 and 2.1.289.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at dev.to →

More in AI

Getting Real Work Out of Two Kimi K2 Conversations: A Prompt Template for Code and Data Tasks

I'm leony, an indie maker. I run kimi-k2.net , a small independent web chat for Kimi models (it calls the Moonshot AI API under the hood, but it isn't affiliated with Moonshot AI).

  • Prompt template structures requests into Objective, Verified context, Constraints, and Output schema
  • Includes request for assumptions and edge cases to catch misunderstandings early
  • Successfully used for generating shell commands, visualizing data, and comparing documents

More from Thursday 8 October →