TL;DR
Todo/task-tracking tools silently removed on newer models. TaskCreate, TaskGet, TaskUpdate, TaskList, and TodoWrite no longer load on Opus 4.8, Sonnet 5, Fable 5, Mythos 5, and newer; set
CLAUDE_CODE_ENABLE_TODO_TOOLS=1to restore them. (more below)Notification hooks now fire for permission prompts in Desktop and VS Code. If your workflow relies on hooks that respond to permission events, they were silently broken in those hosts until this fix.
Runaway builds can no longer stall your session on Linux. Set
CLAUDE_CODE_TOOL_MEMORY_LIMITto cap memory for Bash tool commands via cgroup; opt-in, default unchanged.2.1.232's Bash permission tightening for Cygwin symlinks and input redirections is reverted. A narrower version will return in a later release; if you added workarounds for the original change, you can drop them. (more below)
New in 2.1.233
2.1.233 (August 15, 2026)
- Added GitLab merge request URL support to the
--worktreeflag and theclaude agentsview (where MRs display as!N) - Added an opt-in
forward_user_identityapps gateway setting on Anthropic upstreams that sends the signed-in user's identity as headers, so a proxy behind the gateway can attribute spend per user - Added opt-in memory cgroup support for Bash tool commands on Linux (
CLAUDE_CODE_TOOL_MEMORY_LIMIT) so a runaway build can't stall the session - Added
CLAUDE_CODE_WEBFETCH_CACHE_TTL_MSenvironment variable to configure the WebFetch session URL cache TTL (default unchanged: 15 minutes) - Fixed cloud sessions occasionally being marked as lost when the environment shut down while Claude was waiting on a permission prompt
- Fixed MCP v2 connections endlessly reopening the subscriptions/listen stream against servers that terminate long-held streams on a fixed timeout (e.g. serverless hosts)
- Fixed Notification hooks not firing for permission prompts when running under Claude Desktop or VS Code
- Fixed idle sessions on Linux sometimes keeping one CPU core at 100% when sandboxing is enabled
- Fixed bundled skill aliases like
/checkupand/reviewreporting "Unknown command" in-pmode or with plugins/MCP loaded when a user or project skill shadows the bundled skill - Fixed skill/command argument substitution to prevent argument values from being re-expanded as template markers
- Fixed Windows paths spelled with the NT
\\??\\device prefix bypassing UNC path validation, closing an NTLM credential-leak vector - Improved
claude self-hosted-runnersession start time: the session branch is now created without rewriting the working tree, and two server round trips no longer block the agent's launch - Improved apps gateway error forwarding: 400/413 errors from Vertex, Foundry, and Claude Platform on AWS upstreams now carry the upstream's own message; fixes a bug with auto-compact on apps gateway
- Improved
claude plugin validateto check a bare.claude/skillsdirectory, reporting SKILL.md files whose frontmatter fails to parse - Improved screen reader mode: the
/effortselector renders as a numbered list with a typed-number prompt, and hint and dialog text is no longer clipped - Improved print mode diagnostics: a
[claude-code:unrecognized_model]line is written to stderr when a request goes out for a model ID Claude Code doesn't recognize; map it withmodelOverridesto silence - Changed the GitHub app setup tip to no longer appear in repositories whose origin remote is on gitlab.com or bitbucket.org; the enterprise marketplace tip now covers non-GitHub internal git hosts
- Todo/task-tracking tools (TaskCreate/Get/Update/List, TodoWrite) are no longer available on Opus 4.8, Sonnet 5, Fable 5, Mythos 5, and newer models; set
CLAUDE_CODE_ENABLE_TODO_TOOLS=1to bring them back - Windows: fixed auto mode repeatedly stopping for manual approval on ordinary
cd <dir> && <command> > fileBash commands (a 2.1.232 regression) - Reverted the 2.1.232 Bash permission changes for Cygwin-style symlinks on Windows and for input redirections (
< file); a narrower version will return in a later release
Notes
Todo tools: a deprecation signal
Prior to 2.1.233, every model had access to task-tracking tools. This release removes them from all models in the Opus 4.8+ generation. The env var CLAUDE_CODE_ENABLE_TODO_TOOLS=1 is the escape hatch, but the direction is clear: newer models are expected to track work inline rather than through dedicated tools. If your workflows, custom agents, or skills depend on TaskCreate or TodoWrite calls, add the env var to your environment now, before you upgrade your model.
2.1.232 partial revert
2.1.232 added two Bash permission tighteners: Cygwin-style symlink writes required approval, and input redirections (< file) got permission-checked like argument spellings. Both are reverted in 2.1.233. The changelog says "a narrower version will return in a later release," which suggests the original scope caught too many legitimate commands. The separate Windows auto mode regression (2.1.232's cd <dir> && <command> > file stopping for manual approval) is fixed independently, so that pain point is resolved even without the broader revert.