← All briefs
Matins
21 changes / 3 actionable / 2 deep dives
Claude Code

TL;DR

  • Remote Control can no longer be enabled from repo-local settings. If .claude/settings.json or .claude/settings.local.json turned it on, move the setting to user scope via /config; the repo-level value now only disables it.

  • ultraplan has been removed. The feature is gone with no stated migration path.

  • Org-restricted model family aliases now step down to the newest allowed model instead of the parent model. If your Team or Enterprise org restricts models, model: opus-style subagent aliases pick the best allowed model in the family rather than falling back to whatever the parent uses.

  • Auto mode now evaluates SendMessage dispatches through the permission classifier (more below). Multi-agent workflows where sessions message each other in auto mode may hit new classifier checks.

New in 2.1.222

2.1.222 (August 5, 2026)

  • Fixed worktree-isolated sessions and their subagents being able to run destructive git commands against the main checkout; isolation now applies to file edits and Bash in every session type
  • Fixed PreToolUse auto-allow hooks bypassing tool restrictions in background agent tasks (summaries, compaction, renames)
  • Fixed /usage-credits on Team and Enterprise showing "you've already sent a usage credit request" for members whose earlier request was dismissed, blocking them from sending a new one
  • Fixed the startup connectivity check hanging and then failing behind an HTTPS proxy; it now uses the same proxy-aware transport as API requests and times out with a clear message
  • Fixed "Connection closed mid-response" errors being reported on responses that had actually completed
  • Fixed /usage overattributing usage to MCP servers: a server's share now reflects only the requests that actually consumed its tool results, instead of every turn after any call to it
  • Fixed sessions not linking to pull requests created after the branch was pushed, including through the GitHub REST API
  • Fixed org-restricted model: opus-style subagent and teammate family aliases dropping to the parent model instead of stepping down to the newest org-allowed model in the family
  • Fixed stream idle timeout firing on custom ANTHROPIC_BASE_URL gateways despite server keep-alive pings arriving on the wire
  • Fixed claude.ai connectors being falsely marked as needing authorization when the session token is invalid (they now show a /login hint instead)
  • Fixed tool errors not being displayed for tools no longer available locally, for example after an MCP server is removed
  • Fixed SendMessage rejecting a long summary (it now truncates instead, so sends no longer fail on a character limit)
  • Fixed the spinner's effort label in a subagent's transcript view showing the session's effort level instead of the subagent's own effort: setting
  • Fixed rare crashes when a file watcher hit a filesystem error or during file-watcher teardown
  • Fixed screen readers re-reading the whole input line on every backspace in --ax-screen-reader mode (end-of-line deletions now echo just the deleted characters)
  • Fixed host model-selection keys not taking precedence over a stale on-disk managed-settings.json when CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST is set
  • Improved auto mode safety: messages sent to other agent sessions via SendMessage are now evaluated by the permission classifier before dispatch
  • Improved the refusal when Claude tries to invoke a skill with disable-model-invocation: Claude is now told to ask you to run the skill instead of replicating its workflow
  • Improved the /diff view, the Remote Control workspace diff, and file-edit diffs in Claude Code on the web sessions to use raw git blob content, ignoring workspace-configured diff drivers and textconv
  • Changed Remote Control auto-start so repo-local settings (.claude/settings.json or .claude/settings.local.json) can no longer turn it on (they can still turn it off); enable it at user scope via /config
  • Removed ultraplan feature

Notes

Auto mode safety continues to tighten

SendMessage between agent sessions now requires permission classifier approval before dispatch. This follows 2.1.210's hardening against indirect prompt injection via subagent content and 2.1.221's cache-efficient permission checks for parallel tool calls. The same release also closes a gap where PreToolUse auto-allow hooks bypassed tool restrictions in background tasks (summaries, compaction, renames).

Anthropic is methodically sealing every path where auto mode operations could skip permission evaluation. If you run multi-agent workflows in auto mode, expect each release to cover more surfaces.