Skip to content

Claude Code v2.1.292

Released · Anthropic

Security fixChanges hooks, MCP server config, permission rules, skills and plugins

What the release notes say

What's changed

  • Added --marketplace <source> to claude plugin install: adds the marketplace if needed, under the same policy checks as claude plugin marketplace add, then installs the plugin from it
  • Added an effort parameter to the Agent tool, so Claude runs a sub-agent at the effort level you ask for
  • Added CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS environment variable to set a longer base delay for the backoff when retrying an overloaded (529) request
  • Added prompt.autocomplete, an event a mod hooks to add its own rows to the prompt box's autocomplete list
  • Added prompt caching to $.model.complete for mods: prompt and system take blocks of text, and cache: true on a block caches the request up to it
  • Added workflow agents to the agent.spawn mod hook, with their run and index, so a mod can refuse them
  • Fixed subagent definitions with permissionMode: auto entering auto mode when auto mode is unavailable (disabled by settings, circuit breaker, or a model that doesn't support it)
  • Fixed sandboxed commands being able to read the staged file copies of /ultrareview uploads under ~/.claude/seed-admin
  • Fixed a managed sandbox read-deny path (and user ones beside it) that appears or re-points mid-session not dropping project grants inside it or ending credential injection from files it covers
  • Fixed a notebook or PDF read on macOS and Windows being able to return a file outside what was approved, through a link swapped in mid-read
  • Fixed a tampered on-disk cache of server-managed settings being able to switch off or unseat the built-in policy plugin while the settings fetch failed
  • Fixed rm -rf on the 8.3 short name or another alternate Windows spelling of the home folder or a drive not being treated as removing it
  • Security: Fixed PreToolUse hook approvals and auto mode bypassing the permission prompt for file reads from network (UNC) paths
  • Fixed a skill's or slash command's allowed-tools rule coming back in a later turn when you leave auto mode or plan mode partway through that turn
  • Fixed NO_PROXY being ignored for Claude Code's own API requests (sign-in, policy, feedback, artifacts) when HTTPS_PROXY is set
  • Fixed an MCP tool with a name longer than 128 characters making every request fail; that tool is now left out and an MCP error names it
  • Fixed claude plugin commands such as marketplace add and install running before an organization's managed settings had loaded on a first run
  • Fixed one-shot claude -p and Agent SDK runs stopping a background command 5 seconds after the final result, and one-shot claude -p runs dropping a scheduled wakeup; both are now waited for
  • Fixed plan mode not being restored when resuming a session from the claude --resume session picker or with /resume
  • Fixed saved scheduled tasks created after /resume, /branch or /clear never firing, and saved tasks ignoring later creates and deletes after two writes to the tasks file milliseconds apart
  • Fixed a background session's /loop silently stopping when the session's process restarted (for example after a crash), because its pending wakeup was lost
  • Fixed Grep and Glob reporting no matches when the file or folder they were given could not be read; Claude now retries once or tells you
  • Fixed the Read tool returning only the first entry, with no error, when a PDF's pages was a list such as "6,9,15"; it now returns an error saying to read each page or range separately
  • Fixed @-mentioned text files over 256KB being left out silently: Claude is now told the file's size and to read it in portions
  • Fixed the usage limit alert repeating once per background agent when agents failed on a limit that had already stopped the main conversation
  • Fixed Remote Control viewers seeing an empty subagent pane for background subagents in sessions hosted by the desktop app or an IDE
  • Fixed cross-session delivery notices showing two sessions with similar names as one recipient, and the expiry notice blaming the desktop app when a terminal session let the message lapse
  • Fixed Send now in the desktop app ending the subagent a turn was waiting on when another message was already queued
  • Fixed /bug, /share and /feedback <text> starting over after Ctrl+O or Ctrl+Z while a report was being sent, and closing as cancelled after it had been sent
  • Fixed /remote-env replacing your saved default environment when you pressed Enter right away: the list now opens on your default, and no row has a check mark when no default is in effect
  • Fixed some pasted text reaching Claude as typed text when several pastes overlapped in one prompt
  • Fixed vim mode leaving the cursor past the end of a line, j/k losing their column on shorter lines, and f/t/F/T/;/, jumping to, or deleting up to, a match on another line of the prompt
  • Fixed /add-dir path box letting Shift+Enter or a paste add a line break, and treating fast-typed "tab", "up" or "down" as those keys
  • Fixed fast typing, input-method text and decomposed accents being dropped while a prompt footer row was selected, and ! leaving the row selected
  • Fixed fullscreen mode sending a full-screen clear on every window resize and Ctrl+L when iTerm2 is detected, which may be what filled iTerm2's scrollback with stale pages
  • Fixed a spurious "could not be examined" note for @-words that name no file when a Read deny rule is set and the working directory is under a symlink
  • Fixed "instruction file not loaded" lines going stale or missing after /cd or a permission change, and added a transcript line when a nested one isn't loaded
  • Fixed a compaction summary that repeated /name letting Claude invoke a skill that is reserved for the user
  • Fixed Write, Edit, NotebookEdit and LSP rows, and single Read, Grep and Glob rows, hiding why a mod denied the call: the row now shows the reason
  • Fixed a cloud session showing a turn that never ended when its worker was stopped just as the turn finished