This totally breaks sandbox / VM isolation if you have Remote Control enabled. This feature isn't just within sessions on a single machine, but can send commands to any session accessible by your account.
Reading "Claude Code instructs the receiving Claude never to change permission settings" and so on in the docs makes it seem like they're using LLM classifiers to determine what commands are safe or not.