← All briefs
Matins
27 changes / 4 actionable / 2 deep dives
Claude Code

TL;DR

  • Bash deny and ask rules now hold when a command follows an environment variable prefix or a bare assignment. Two bypass paths (e.g. TZ="$HOME" rm -rf build) that let commands slip past sandbox deny rules are closed.

  • agent.spawn now supports teammates, with a single agent ID across plugin hook events. Mod authors also get idle and waiting states in $.agent.list().

  • [VSCode] A 2.1.288 auth regression that may have caused frequent sign-outs is reverted. If 2.1.288 kept signing you out, update.

  • Mods stabilized after the 2.1.287 launch: ~20 crash, rendering, and fault isolation fixes (more below). If you saw mods failing to draw, crashing sessions, or not loading after upgrade, this release is the checkpoint.

New in 2.1.289

2.1.289 (October 4, 2026)

  • Fixed a deny or ask rule on a nested part of a compound shell command not holding over a user-installed mod's approval on managed machines
  • Fixed the terminal freezing on short code blocks with many unclosed <script> tags or deeply nested ${ substitutions
  • Fixed Read deny rules not applying to files @-mentioned, changed, or selected in the IDE through a symlink
  • [VSCode] Reverted a 2.1.288 change to claude auth status that may have made sign-outs more frequent
  • Improved how quickly large files open in a plugin code pane by laying the highlighted view out once at its final width
  • Fixed plugin list, plugin eval and plugin update showing a stale copy of a plugin installed from a local folder marketplace, and hot reload for a symlinked --plugin-dir
  • Fixed installed mods not loading in the first session after an upgrade
  • Fixed a plugin's rows above the prompt showing a stale row while the Background tasks dialog was open in fullscreen
  • Fixed plugin panes drawing nothing when a link used a localhost address, an @ in its path, an uppercase host or a file: path
  • Fixed a user-installed plugin being able to rewrite the descriptions of an organization-managed MCP server's sign-in tools
  • Fixed a freeze or forced quit at launch when a plugin drew a Box with a border style the terminal does not know
  • Fixed supervised and background sessions ending when a plugin's on-screen handler threw asynchronously
  • Fixed sessions ending with an interface error when a plugin region with no height kept growing
  • Fixed Bash deny and ask rules missing a command behind an environment variable prefix with an expanded value (e.g. TZ="$HOME" rm -rf build) when the sandbox auto-allows commands
  • Fixed a Bash deny or ask rule being skipped under sandbox auto-allow when a bare variable assignment came before the command
  • Fixed claude plugin validate skipping the plugin when the folder also holds a marketplace manifest
  • Added agent.spawn for teammates, one agent id across plugin hook events, and idle and waiting states in $.agent.list()
  • Fixed sessions ending with "unrecoverable interface error" when a value a mod's ui.render hook wrote made a row throw while drawn; the engine now draws its own row instead
  • Fixed text with a tab, a stray escape and a C1 control, or a short text with a tab and CRLF line endings, drawing over the rows below it
  • Fixed right-aligned content in a mod's pane or band drawing under the close mark or [-], which now also keep one column in from the terminal's edge
  • Fixed a mod's Client that fails while drawn taking down everything the mod drew around it; it now fails alone and raises ui.fault
  • Fixed claude plugin validate failing an Anthropic marketplace's own plugin and listing a clean plugin.json in --json
  • Fixed a mod's band that fails to draw briefly telling the cards under it to step aside
  • Fixed a failed plugin component showing Error or nothing as its reason when the failure carried no message
  • Improved the line a mod's author sees when its band or pane fails to draw: it names the mod and says nothing was drawn
  • Fixed published artifact pages freezing or crashing the reader's browser tab on short code blocks with many unclosed <script> tags
  • Fixed a mod's Client region staying failed for the whole session after the terminal threw while drawing it

Notes

Mods stabilization after 2.1.287 launch

The mod system launched two days ago in 2.1.287, and 2.1.289 is the first serious stabilization pass. This release carries about 20 fixes targeting mod and plugin rendering, lifecycle, and fault isolation. The key pattern: mods that fail now fail alone. A Client region that throws no longer takes down everything the mod drew around it (it raises ui.fault instead). A ui.render hook that returns a bad value no longer ends the session with "unrecoverable interface error"; the engine draws a fallback row. Background and supervised sessions no longer die when a mod's handler throws asynchronously.

If you held off on building mods because of the early instability, this is the checkpoint to revisit. The two-day cadence from launch to stabilization pass suggests Anthropic shipped 2.1.287 knowing the edges were rough and planned this follow-up. The agent.spawn addition for teammates is also mod-ecosystem infrastructure, not just a bug fix sweep.