Summary
configs/claude-code/CLAUDE.md tells the model that curl, wget, inline HTTP and WebFetch are blocked and replaced with an error, but on the installed plugin those tools are not denied. The instruction describes behavior the code doesn't have, so the model routes around a wall that isn't there — and is told not to retry a call that may have failed for an ordinary transient reason.
The instruction
configs/claude-code/CLAUDE.md, lines 9-20:
## BLOCKED — do NOT attempt
### curl / wget — BLOCKED
Intercepted and replaced with error. Do NOT retry.
...
### Inline HTTP — BLOCKED
`fetch('http`, `requests.get(`, ... — intercepted. Do NOT retry.
...
### WebFetch — BLOCKED
What the code does (v1.0.169)
Every action: "deny" in hooks/core/routing.mjs is a security-policy match, not a network-tool rule:
return { action: "deny", reason: `Blocked by security policy: matches deny pattern ${result.matchedPattern}` };
Network tools take the redirect path instead — from hooks/pretooluse.mjs:
// routing.mjs attaches `redirectMeta` to decisions for tools whose output we
// kept out of the model's context window (curl/wget, WebFetch, large Read).
Keeping a large output out of context is not the same thing as blocking the call, and Do NOT retry doesn't follow from it either.
Repro
In a Claude Code session with the plugin active (v1.0.169), run any curl. Six curl invocations in one session all executed and returned their output; the PreToolUse hook emitted the advisory <context_guidance> tip, not a denial.
Suggested fix
State it as a routing preference rather than a prohibition, e.g.:
Prefer ctx_fetch_and_index(url, source) + ctx_search(queries) over WebFetch, over curl/wget in Bash, and over inline fetch(/requests.get( — reach for a direct fetch only when you need the exact bytes and the sandbox can't provide them.
Two smaller things in the same file, if useful:
- Internal contradiction: line 11 lists
curl as BLOCKED; line 47 recommends curl inside ctx_batch_execute(commands: [...], concurrency: 5).
- Drifted duplicate: the repo carries a second copy at the root (
CLAUDE.md) which already disagrees with configs/claude-code/CLAUDE.md on two lines (language: "shell" vs language: "javascript" for the Grep and Bash guidance). Generating one from the other would stop them separating further.
Summary
configs/claude-code/CLAUDE.mdtells the model thatcurl,wget, inline HTTP andWebFetchare blocked and replaced with an error, but on the installed plugin those tools are not denied. The instruction describes behavior the code doesn't have, so the model routes around a wall that isn't there — and is told not to retry a call that may have failed for an ordinary transient reason.The instruction
configs/claude-code/CLAUDE.md, lines 9-20:What the code does (v1.0.169)
Every
action: "deny"inhooks/core/routing.mjsis a security-policy match, not a network-tool rule:Network tools take the redirect path instead — from
hooks/pretooluse.mjs:Keeping a large output out of context is not the same thing as blocking the call, and
Do NOT retrydoesn't follow from it either.Repro
In a Claude Code session with the plugin active (v1.0.169), run any
curl. Sixcurlinvocations in one session all executed and returned their output; thePreToolUsehook emitted the advisory<context_guidance>tip, not a denial.Suggested fix
State it as a routing preference rather than a prohibition, e.g.:
Two smaller things in the same file, if useful:
curlas BLOCKED; line 47 recommendscurlinsidectx_batch_execute(commands: [...], concurrency: 5).CLAUDE.md) which already disagrees withconfigs/claude-code/CLAUDE.mdon two lines (language: "shell"vslanguage: "javascript"for the Grep and Bash guidance). Generating one from the other would stop them separating further.