← All briefs
Matins
92 changes / 4 actionable / 3 deep dives
Claude Code

TL;DR

  • MCP servers now negotiate protocol version 2026-07-28 by default on every install, including Bedrock, Vertex and Foundry. If a local stdio server breaks after updating, set MCP_PROTOCOL_NEGOTIATION=legacy to opt out (more below).

  • The Agent tool takes an effort parameter, so you can set a sub-agent's reasoning effort explicitly. Useful when a delegated task needs deeper thinking, or when a quick lookup should stay cheap.

  • Seven security fixes patch sandbox and permission bypasses, including UNC path reads, tampered settings caches, and notebook/PDF link-swap attacks. Update promptly; several allowed reads or writes outside approved paths (more below).

  • claude plugin test now fails when a hook's expect fails or the engine refuses a stub answer, instead of passing silently. Re-run your plugin test suite; real failures may have been hiding (more below).

New in 2.1.292

2.1.292 (October 7, 2026)

  • Added --marketplace <source> to claude plugin install: adds the marketplace if needed, under the same policy checks as claude plugin marketplace add, then installs the plugin from it
  • Added an effort parameter to the Agent tool, so Claude runs a sub-agent at the effort level you ask for
  • Added CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS environment variable to set a longer base delay for the backoff when retrying an overloaded (529) request
  • Added prompt.autocomplete, an event a mod hooks to add its own rows to the prompt box's autocomplete list
  • Added prompt caching to $.model.complete for mods: prompt and system take blocks of text, and cache: true on a block caches the request up to it
  • Added workflow agents to the agent.spawn mod hook, with their run and index, so a mod can refuse them
  • Fixed subagent definitions with permissionMode: auto entering auto mode when auto mode is unavailable (disabled by settings, circuit breaker, or a model that doesn't support it)
  • Fixed sandboxed commands being able to read the staged file copies of /ultrareview uploads under ~/.claude/seed-admin
  • Fixed a managed sandbox read-deny path (and user ones beside it) that appears or re-points mid-session not dropping project grants inside it or ending credential injection from files it covers
  • Fixed a notebook or PDF read on macOS and Windows being able to return a file outside what was approved, through a link swapped in mid-read
  • Fixed a tampered on-disk cache of server-managed settings being able to switch off or unseat the built-in policy plugin while the settings fetch failed
  • Fixed rm -rf on the 8.3 short name or another alternate Windows spelling of the home folder or a drive not being treated as removing it
  • Security: Fixed PreToolUse hook approvals and auto mode bypassing the permission prompt for file reads from network (UNC) paths
  • Fixed a skill's or slash command's allowed-tools rule coming back in a later turn when you leave auto mode or plan mode partway through that turn
  • Fixed NO_PROXY being ignored for Claude Code's own API requests (sign-in, policy, feedback, artifacts) when HTTPS_PROXY is set
  • Fixed an MCP tool with a name longer than 128 characters making every request fail; that tool is now left out and an MCP error names it
  • Fixed claude plugin commands such as marketplace add and install running before an organization's managed settings had loaded on a first run
  • Fixed one-shot claude -p and Agent SDK runs stopping a background command 5 seconds after the final result, and one-shot claude -p runs dropping a scheduled wakeup; both are now waited for
  • Fixed plan mode not being restored when resuming a session from the claude --resume session picker or with /resume
  • Fixed saved scheduled tasks created after /resume, /branch or /clear never firing, and saved tasks ignoring later creates and deletes after two writes to the tasks file milliseconds apart
  • Fixed a background session's /loop silently stopping when the session's process restarted (for example after a crash), because its pending wakeup was lost
  • Fixed Grep and Glob reporting no matches when the file or folder they were given could not be read; Claude now retries once or tells you
  • Fixed the Read tool returning only the first entry, with no error, when a PDF's pages was a list such as "6,9,15"; it now returns an error saying to read each page or range separately
  • Fixed @-mentioned text files over 256KB being left out silently: Claude is now told the file's size and to read it in portions
  • Fixed the usage limit alert repeating once per background agent when agents failed on a limit that had already stopped the main conversation
  • Fixed Remote Control viewers seeing an empty subagent pane for background subagents in sessions hosted by the desktop app or an IDE
  • Fixed cross-session delivery notices showing two sessions with similar names as one recipient, and the expiry notice blaming the desktop app when a terminal session let the message lapse
  • Fixed Send now in the desktop app ending the subagent a turn was waiting on when another message was already queued
  • Fixed /bug, /share and /feedback <text> starting over after Ctrl+O or Ctrl+Z while a report was being sent, and closing as cancelled after it had been sent
  • Fixed /remote-env replacing your saved default environment when you pressed Enter right away: the list now opens on your default, and no row has a check mark when no default is in effect
  • Fixed some pasted text reaching Claude as typed text when several pastes overlapped in one prompt
  • Fixed vim mode leaving the cursor past the end of a line, j/k losing their column on shorter lines, and f/t/F/T/;/, jumping to, or deleting up to, a match on another line of the prompt
  • Fixed /add-dir path box letting Shift+Enter or a paste add a line break, and treating fast-typed "tab", "up" or "down" as those keys
  • Fixed fast typing, input-method text and decomposed accents being dropped while a prompt footer row was selected, and ! leaving the row selected
  • Fixed fullscreen mode sending a full-screen clear on every window resize and Ctrl+L when iTerm2 is detected, which may be what filled iTerm2's scrollback with stale pages
  • Fixed a spurious "could not be examined" note for @-words that name no file when a Read deny rule is set and the working directory is under a symlink
  • Fixed "instruction file not loaded" lines going stale or missing after /cd or a permission change, and added a transcript line when a nested one isn't loaded
  • Fixed a compaction summary that repeated /name letting Claude invoke a skill that is reserved for the user
  • Fixed Write, Edit, NotebookEdit and LSP rows, and single Read, Grep and Glob rows, hiding why a mod denied the call: the row now shows the reason
  • Fixed a cloud session showing a turn that never ended when its worker was stopped just as the turn finished
  • Fixed cloud sessions with a large transcript sometimes asking for a permission again after it was approved
  • Fixed scheduled tasks and other queued notifications being lost in cloud sessions when a message was retried or edited while Claude was reading them
  • Fixed cloud sessions forgetting the thinking setting chosen in the client when the session's container restarted
  • Fixed Cowork cloud sessions saying a proxy blocked artifacts when Anthropic couldn't confirm the organization's settings
  • Fixed plugins whose hooks module makes many $.state calls through one const taking minutes to load or validate
  • Fixed claude plugin validate listing a matcher or state value for a hooks module that the engine reads from elsewhere
  • Fixed claude plugin validate listing a $.state value read through a top-level var that was declared again or reassigned; such a module is now refused
  • Fixed a plugin's served $ method restarting the hook origin, which could run a guard hook with a .catch above it again without end
  • Fixed plugin interface calls made while the plugin hooks worker restarts running without the hooks other plugins put on them
  • Fixed a mod's config.set, state.set, env.set or agent.spawn hook that denies after calling next(e) being answered as a refusal: the hook is now reported as failed, by name
  • Fixed /theme, the /config Theme menu and the first-run theme step saving a theme before a plugin's config.set hook was asked
  • Fixed a plugin's tool.check hook answering allow running a tool that requires your answer (a question, a plan approval) without showing its dialog
  • Fixed a mod's start-up prompt, command or subagent being queued a second time when the hooks worker was replaced
  • Fixed a mod's hook that called next(e) and then failed while the turn was interrupted letting the call through; the call is now rejected
  • Fixed a plugin's prompt drop or setting deny being ignored when its reason was longer than 4,096 characters
  • Fixed an organization's plugin being unloaded on its own reload, or after another plugin crashed, when it returned a $ name that a user-installed mod had added; the mod is now unloaded instead
  • Fixed tool calls made while the plugin hooks worker restarts being answered without the plugins' permission hooks
  • Fixed plugin tool.call hooks seeing some tool calls before misnamed parameters were repaired; a hook now sees the arguments the tool will run with
  • Fixed a mod's guard hook with a .catch being skipped silently for calls another mod's hook makes beneath the guard's own $ call; its .catch is now asked
  • Improved startup of claude -p and SDK sessions: the first turn no longer waits for HTTP and SSE MCP servers to answer resources/list
  • Improved rendering speed of long bulleted or numbered replies: they stream, resize and re-open in the transcript (ctrl+o) much faster
  • Improved Ctrl+C draft recovery: a cleared prompt now stays reachable with Up after a slash command or a sent message
  • Improved hook output handling: <system-reminder> tags written in a hook's output are escaped before they reach Claude
  • Improved tool input handling: Grep accepts file_path for path, and Write, WebFetch and Read ignore a few stray parameters instead of failing the call
  • Improved the steps shown when a marketplace declared in a settings file has a name that looks like an official Anthropic marketplace
  • Improved sandbox auto-allow: with strict sandbox mode set in user, managed or --settings settings, an interpreter command with an env var prefix like FOO=bar python3 app.py runs unprompted
  • Improved the Artifact tool's listing: Claude now sees how many published artifacts you have and can list up to 200 at once instead of 50
  • Improved cloud sessions after a restart: Claude is now told which stopped background agents it can resume by id
  • Improved the Claude in Chrome message in claude.ai cloud sessions when the browser can't be reached: Claude is now told it may continue with alternatives if the user prefers
  • Improved the /focus tip: it now invites you to try focus view mid-turn and shows how to switch back
  • Improved startup with local (stdio) MCP servers that ignore the newer protocol check: after one slow connect they are remembered for 7 days and connected the older way without the wait
  • Changed local (stdio) MCP server connections to negotiate protocol version 2026-07-28 by default on every install, including Bedrock, Vertex and Foundry; MCP_PROTOCOL_NEGOTIATION=legacy opts out
  • Changed claude plugin test: a failed expect inside a hook the test registered, or a stub answer the engine refuses, now fails the test instead of passing silently
  • Changed usage limit messages to write claude.ai settings links with https:// so terminals and apps can make them clickable
  • Changed scheduled and Run now routine runs to publish a new artifact only you can see without asking for approval; artifacts that request connectors or other access still ask
  • Changed agent names to allow at most 256 characters: a longer one is rejected, and a skill's or a plugin file's name longer than that is ignored
  • [Cloud sessions] Fixed routine runs occasionally staying listed as running for hours after they had finished
  • [Cloud sessions] Fixed editing or duplicating a routine turning off its push notifications when the routine had no saved notification setting
  • [Cloud sessions] Fixed SVG, HEIC, TIFF and other less common image files failing to attach; they now attach as regular files
  • [Cloud sessions] Fixed approval prompts offering "Always allow" for connector tools that an organization set to require approval; the choice had no effect
  • [Remote Control] Fixed the first message of a new Remote Control session started from claude.ai/code accepting only images; it now accepts PDFs and other files like later messages
  • [Claude Tag] Added an Edit button to the Allowed domains card on a channel's Configure page, so Enterprise admins can open the access bundle that sets the channel's domains
  • [Claude Tag] Fixed replies sent in a Slack thread while Claude was still on its first request there being held until that request finished, or missed when sent seconds apart
  • [Claude Tag] Fixed Slack threads woken only by GitHub pull request activity or a routine staying on their original model after an admin changed the channel or workspace default model
  • [Claude Tag] Fixed Claude sometimes posting a spend limit notice in Slack when the real cause was that your organization had run out of usage credits
  • [Claude Tag] Fixed a session hanging until interrupted when a permission prompt that can't be answered from Slack was denied automatically
  • [Claude Tag] Improved @Claude !status in a channel to say when Claude has stopped reading its untagged messages, why, and that an @-mention starts it reading again
  • [Claude Tag] Changed the first message of a Slack thread continued with !fork to a card showing where it came from, the request, and who asked, with a link to the original thread
  • [Claude Tag] Changed the organization-wide and default spend limit boxes on Claude Tag's spend limits page in admin settings to save only when you press Save or Enter, not when you click away
  • [Code Review] Added the period's total with its change from the previous period, and a breakdown by repository, to the PRs reviewed chart in Code Review analytics
  • [Code Review] Fixed a queued review failing when the pull request moved to a new base branch and the old one was deleted; the commit is now re-queued for review
  • [Code Review] Fixed reviews ignoring a CLAUDE.md's rules when the pull request edits that file; reviews now use its version from the base branch

Notes

MCP protocol negotiation defaults changed

Local stdio MCP servers now negotiate protocol version 2026-07-28 on every fresh connection. This includes Bedrock, Vertex and Foundry setups. If you maintain an MCP server that hasn't adopted the newer protocol handshake, your first connect after updating will be slow while Claude Code learns it needs the old path. After that one slow connect, the server is remembered for 7 days and connected the older way without the wait. Set MCP_PROTOCOL_NEGOTIATION=legacy to opt out entirely. This follows 2.1.287's broader MCP protocol work, where URL prompts from servers on the 2025-11-25 protocol were added and bareElicitationCapability was introduced as a compatibility flag.

Plugin test correctness tightened

claude plugin test was silently swallowing real failures. A failed expect inside a hook or a stub answer the engine refused would pass the test. This is now fixed, so existing green suites may turn red on this version. The fix is intentional: if your suite was green before, either the hooks were correct and will stay green, or they had real problems the test framework was masking.

Security fixes: sandbox and permission bypass cluster

This release patches seven distinct ways to read or write outside approved paths. The most broadly relevant: PreToolUse hook approvals and auto mode were bypassing the permission prompt for reads from network (UNC) paths, and a tampered on-disk cache of server-managed settings could switch off the built-in policy plugin while the settings fetch failed. The notebook/PDF link-swap attack (where a link changed mid-read could return a file outside what was approved) was also fixed on both macOS and Windows. 2.1.290 fixed the same pattern for images, making this the second beat of link-swap hardening in two days. If you run Claude Code in a shared or adversarial environment, update before your next session.