Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.242 Home All releases olderv2.1.241 v2.1.243newer
Claude Code v2.1.242

Computer use caps what Claude can be granted per app class

You'll notice
Useful3 Signal3
Computer Use

Browsers can only be seen, terminals only clicked, and Claude's own app never granted.

What

When Claude asks for control of an application, browsers can now only ever be granted see-only access, terminals and IDEs only clicking (no typing or pasting), and Claude's own application can never be granted at all, because that would let the model change its own permissions.

Details
  • Browser refusals point the model at the Claude in Chrome extension MCP for actual interaction; terminal and IDE refusals point it at Bash.
  • Browser and terminal refusals allow one re-request in the same turn, confirmed once, and that allowance expires at the end of the turn.
  • First-request warnings can be turned off ahead of time with skipFirstRequestWarnings.
Evidence

You requested access to Claude's own application.

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.242 →