Skip to content

[FAQ] Why can't the headless Claude Code agent run uv, docker compose or curl on Windows even though they are in --allowedTools? #439

Description

@mrfmanuel

Course

ai-dev-tools-zoomcamp

Question

In Homework 4 (incident responder), my service starts Claude Code in headless mode with claude -p ... --allowedTools "Bash(uv *) Bash(docker compose *) Bash(curl *)". The agent diagnoses the bug and edits the code, but every uv run, docker compose and curl command is blocked and it says it cannot get approval. Why, and how do I fix it on Windows?

Answer

On Windows, Claude Code can run shell commands through its PowerShell tool instead of Bash. Bash(...) rules in --allowedTools only cover the Bash tool, so commands that go through PowerShell are not allowlisted and, in headless mode (-p), nobody can approve them, so they are denied. Editing files with Read/Edit/Write still works, which is why the agent can diagnose and change the code but cannot run tests, rebuild or verify.

Fix: allowlist the same commands for the PowerShell tool as well, for example:

--allowedTools "Read Edit Write Bash(uv *) Bash(docker compose *) Bash(curl *) PowerShell(uv *) PowerShell(docker compose *) PowerShell(curl.exe *) PowerShell(git status) PowerShell(git diff *)"

Tip 1: test the permissions before the real incident with a throwaway claude -p run that only runs docker compose ps, curl.exe -s http://localhost:8000/healthz and uv run pytest -q.

Tip 2: keep the list narrow. Do not allow git push or delete commands, and note that a broad rule like uv * also allows uv run python -c ....

Tip 3: in PowerShell use curl.exe, because plain curl is an alias for Invoke-WebRequest.

Checklist

  • I have searched existing FAQs and this question is not already answered
  • The answer provides accurate, helpful information
  • I have included any relevant code examples or links
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions