Skip to content

Claude Code v2.1.287

Released · Anthropic

BreakingSecurity fixChanges skills and plugins, hooks, MCP server config, agent context files, context and compaction settings, permission rules, slash commands

What the release notes say

What's changed

  • Added Claude Mods: plugins may now modify deeper behavior

  • Added You should know, a built-in mod where a side agent watches your back and flags things you or Claude might miss. Turn it on with /plugin enable cc-plugin-you-should-know@builtin (for first-party sessions with telemetry on)

  • Added an n:<text> filter to the agents view that matches session names and tasks; a filter now shows matches in collapsed sections and Enter opens the first match

  • Added prompt_text to the OpenTelemetry user_prompt event, a copy of prompt for backends that nest dotted keys; drop or mask it wherever you drop or mask prompt (anthropics/claude-code#70763)

  • Added URL prompts from MCP servers on the 2025-11-25 protocol, for example to sign in. If a server no longer connects after this update, add "bareElicitationCapability": true to its MCP config entry

  • Windows: Added a startup warning when denying the Bash tool also turns off the PowerShell tool, so Claude has no shell tool

  • Self-hosted runner: Added a built-in gh api (REST only) for sessions that use Anthropic-managed git on macOS and Linux machines where the GitHub CLI is not installed

  • Fixed fast mode staying off in remote sessions owned by an agent with no user account, even when the organization allows it

  • Fixed Remote Control not receiving messages for minutes at a time when a reconnect request got no response; it now gives up after 30 seconds and retries

  • Fixed hooks configured with asyncRewake waking Claude over and over with "found issues" notifications when the hook's script file is missing; the broken hook is now reported once

  • Fixed tool heartbeats not reaching SDK hosts while the model's response stream was stalled with no data arriving

  • Fixed Bedrock and Vertex startup model checks ignoring an enforced availableModels list, which could collapse /model to one Opus row

  • Fixed the Claude in Chrome browser picker showing a JSON parse error when Chrome could not be reached

  • Fixed picking Fable in /model on a claude.ai login saving the current version's id, so your saved default now follows the newest Fable like Opus and Sonnet do

  • Fixed switching between Opus 5.5 and Sonnet 5.5 (/model, opusplan) rewriting earlier MCP tool announcements, which could drop earlier extended thinking

  • Fixed Amazon Bedrock Guardrails blocks that arrive mid-response ending the turn with an API error instead of the guardrail's message when the reply began with thinking

  • Fixed a dangerous rm (such as one on / or the home directory) losing its always-ask safeguard when the same command also redirected output to a ~ or wildcard path

  • Fixed claude -p and SDK sessions repeating a model fallback on every later message after the model was switched while a reply was running

  • Fixed a folder's CLAUDE.md being attached a second time after resuming a session or after a compaction

  • Fixed background sessions that could not be reopened from claude agents after the agent exited and removed the worktree the session was started in

  • Fixed /advisor pairing checks: Sonnet 5.5 can now advise Opus 4.7 and 4.8, and advisors the API would refuse are flagged up front instead of being silently dropped

  • Fixed Bash permission prompts showing internal parser names such as "Contains simple_expansion" instead of a plain explanation

  • Fixed a cause of fullscreen sessions on slow or busy machines exiting with "Claude Code exited after an unrecoverable interface error" while a scroll key was held in a long conversation

  • Fixed organization per-tool permission ceilings being silently dropped for an MCP tool named __proto__

  • Fixed Claude being told to page large MCP results saved as JSON with Read's offset and limit, which cannot split one long line

  • Fixed the commit attribution reminder being delivered inside a tool result after a compaction

  • Fixed screen reader mode leaving the cursor away from the typed text in search boxes (such as /resume and /permissions) and sign-in code fields

  • Fixed screen reader mode refusing Enter with nothing typed on /rewind's summarize options, whose added context is optional

  • Fixed screen reader mode showing a "Tab to amend" hint on approval prompts, where Tab does nothing

  • Fixed screen reader mode listing arrow keys that do nothing in /permissions and /mcp, and saying "Select with numbers" in empty menus or while a search box has the keys

  • Fixed screen reader mode leaving out the changed lines in file edit approval prompts and other diffs

  • Fixed screen reader mode sending the claude --teleport progress screen, and an MCP form field while it is being checked, to the screen reader again on every spinner frame

  • Fixed CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS not removing the structured-output format from session-title and prompt-hook requests, which Bedrock-backed gateways reject

  • Fixed screen reader mode leaving out the top lines of a second approval prompt, a changed /config row or the rejected-plan line when the previous screen was taller than the terminal window

  • Fixed --include-partial-messages sending a cut-short reply's message_stop late or never, so apps could show the reply as still in progress

  • Fixed claude agents sometimes not showing the permission prompt a background session is waiting on

  • Fixed /ultrareview giving advice about .git/info/attributes when the upload stops on a committed .gitattributes it cannot read, such as one saved as UTF-16

  • Fixed claude remote-control failing to register behind an HTTP proxy with a misleading "Check your organization permissions" error (anthropics/claude-code#97352)

  • Fixed sandboxed Bash commands on Linux inheriting an open handle on the Claude Code executable

  • Fixed the running-tool dot and three spinners still moving with the "Reduce motion" setting on, and /rewind's confirm screen updating its "ago" time while you type a note