Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.283 ·

Tool calls can be sent to an attached machine with _host when CLAUDE_CODE_REMOTE_TOOLS_FORWARD is set

With CLAUDE_CODE_REMOTE_TOOLS_FORWARD set, tools gain a _host field for running on an attached machine, with new Bash guidance and classifier rules

Group of 6 Use it now No documentation found Improvements
JSON All of v2.1.283
Use it nowTier: how much it should matter to you
5Useful: my rating, 1 to 5
5Signal: worth watching, 1 to 5
Remote ToolsArea: what it touches
ImprovementsKind: in v2.1.283,
What probably matters to youSection of the release

What

Running a tool call on an attached machine (such as the user's own computer, connected to a cloud session) used to be compiled out entirely. It is now controlled by the environment variable CLAUDE_CODE_REMOTE_TOOLS_FORWARD. When it is true:

  • Tools get an optional _host input field naming the attached machine to run the call on. Leaving it out runs the call in the session's own environment, the default. Input clean-up now keeps _host on Bash, Edit and Write calls.
  • Calls naming a machine are checked. File and search tools only pass when the call can actually be forwarded. Edit (errorCode 14) and Bash (errorCode 11) reject a call that names a machine but was not forwarded to it, and tell Claude to omit the field.
  • The Bash tool description gains a "# Machines" section telling Claude to route commands to an attached machine with a per-call parameter, and never to sleep or poll for a machine that has gone offline. This section also needs a second check to pass. The stock Bash and Write descriptions captured under this release are unchanged.
  • Transcript processing now handles tool_host_result_lines attachments, which were hardcoded off before.
  • The transcript sanitiser brackets a key named result_from like other reserved names, so tool output cannot pass itself off as that marker.
  • The auto-mode classifier prompt gains a section, "## Calls served by an attached machine". It says output from calls marked "_host" or result_from is the user's private data from another machine. Sending that data to a network destination, git remote or external service from the session's own environment is judged as cross-machine data movement under Data Exfiltration.

The variable has to come from the real process environment: a settings file cannot turn it on. It is also stripped from the environment that child processes inherit.

The guard for incoming remote-control messages changed too. guardedFamilies() now switches hook and plugin forwarding off outright. Before, these were decided by CLAUDE_CODE_DISABLE_HOOK_FORWARDING, CLAUDE_CODE_DISABLE_PLUGIN_FORWARDING, CLAUDE_CODE_REMOTE_SESSION_ID and CLAUDE_CODE_ENTRYPOINT. Remote tools are on only when CLAUDE_CODE_REMOTE_TOOLS_FORWARD is true and CLAUDE_CODE_REMOTE_TOOLS_SESSION_CHANNEL is not false. With forwarding on, incoming messages also pass a session-channel check that can drop them.

Why

This is the first build in which Claude can be told to run Bash, Read, Write, Edit, Grep or Glob on another machine the user attached. The safety rules were extended with it, so data fetched from the user's machine is treated as private. None of it applies unless the process environment sets the variable. Hook and plugin forwarding over the remote-control channel no longer follows the old variables.

Read from
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe second condition needed for the section to appear, and the name of the per-command setting for choosing a machine, are not known.
The name it cites is new in this buildNew in this build: CLAUDE_CODE_REMOTE_TOOLS_FORWARD

See this entry in the whole of v2.1.283 →

Feedback