Claude code had safeguards like that hardcoded into the software. You could see it if you intercept the prompts with a proxy