Follow Discord
Writing the changelog v2.1.284 compose entry prose · 2/5 waiting for the next tick

First lookThis one went up minutes after the release hit npm, off a quick read of the bundle, so it's thin and some of it will change. The full changelog replaces this page when the deep run finishes.

Found so far434 raw findings from the deep run, still being written up. Last one in at . The written-up page replaces them when it lands.

  1. Hook debug log now separates stdout and stderr and includes the exit status

    Hook result logging now prints labelled `stdout:` and `stderr:` sections when a hook fails or writes to stderr. It appends ` status code N` on an error outcome, and logs errors at error level (debug otherwise). Failed hooks with no output are now logged too.

  2. /recap refuses requests that did not come from the user in this session Gated

    /recap now returns a fixed refusal instead of a recap when the request was not submitted by the user in this session. That covers messages relayed from Slack, Teams or a project thread, and messages sent by a routine or another program. A verified Slack human turn is still accepted.

  3. /autofix-pr stands down on PRs already handled by PR Steward (behind tengu_federated_flask) Gated

    Behind a new flag, /autofix-pr now asks `gh pr view` for the PR's labels as well. If the PR carries `claude-pr-steward-watching` or `claude-pr-steward-is-working`, it refuses to take the PR on and explains the options: leave it, make one change and hand back, or take over by removing the label. The same result is returned when the server's subscribe call answers `pr_steward_owns_binding`; in that case a cloud session that was just spawned is archived. The in-session poll cron prompt also gains instructions not to fix or push while those labels are present, and cloud autofix sessions get extra instructions appended to their initial message.

  4. /auto-mode-setup checks login before scanning, with new error messages

    Propose mode of the auto-mode setup tool now runs a login check first. If that check does not return ok, setup returns an error code of `login_expired` or `not_logged_in`, logs `auto_mode_setup_propose`, and tells the user to run /login and then re-run /auto-mode-setup. The check passes when an API key or apiKeyHelper is present.

  5. Memory-file write lint (refuse or strip invisible characters and harness-tag text) is built but gated off by default Gated

    This build adds a lint to Write and Edit when they target memory-directory .md files. Interactive (main-session) writes are refused if the path or content contains invisible or control characters, or text shaped like a harness tag such as <system-reminder>. Background or subagent writes have those characters stripped instead of being refused. An Edit that becomes a no-op after the stripping is refused. Each action is logged as the tengu_memdir_write_lint event. The predicate that turns the lint on (vbe) needs the file to be a memory-dir .md file AND `x(FRn, !1)` with `FRn = "tengu_memdir_write_lint"`. That makes the compiled fallback false, so the lint is off unless remote config turns it on.

  6. Linux sandbox handles running as root without CAP_SETFCAP

    When running as uid 0 without CAP_SETFCAP, the Linux sandbox now probes bwrap with `--unshare-user` and, if the probe fails, reports a dependency error explaining that every sandboxed command would fail writing the uid map. It also logs a one-time warning. `--cap-drop ALL` now comes from a helper that adds `--cap-add CAP_SETFCAP` for root with setfcap when the seccomp helper is in use.

  7. Auto-mode security classifier gains a 'candidate' prompt wording behind tengu_marble_finch or an env var Gated

    The auto-mode classifier's system prompt now takes a wording argument, either 'baseline' or 'candidate'. The candidate wording extends the Bound rule to connected apps and accounts. It adds tails about bypass text and unseen tool results, and adds a block of rules: UNVERIFIABLE GESTURES, SIDE-DOOR ACTIONS, TOOL EFFECT, WHICH CALL IS BEING JUDGED, SECRETS AS LABELS, RESTRICTED DESTINATIONS and COPIES CARRY THEIR SHARING. Which wording is used comes from CLAUDE_CODE_AUTO_MODE_CANDIDATE_WORDING if set, then the tengu_marble_finch gate (fallback false), otherwise baseline. If a build cannot render a wording intact, it falls back to baseline and logs a warning. Classifier telemetry now records the wording used.

  8. Artifact database: new read-only 'view' level for as_level

    `as_level` on artifact read_db/write_db now also accepts "view", meaning someone who can only view the artifact. The tool descriptions now say "view" for someone who can only view the artifact, "interact" for a signed-in viewer who can use it, and "admin" for someone who can edit it. A write_db at as_level 'view' is refused locally before anything is sent.

  9. `sonnet` alias now resolves to Sonnet 5.5 (claude-sonnet-5-5) on first-party

    In the built-in model catalog, the `sonnet` alias's default changed from claude-sonnet-5 to claude-sonnet-5-5. The catalog adds a Sonnet 5.5 entry (display_name "Sonnet 5.5", 1M context window) and lists it as the latest sonnet. Some providers keep their own mappings: bedrock, vertex, foundry and mantle stay on claude-sonnet-4-5, and anthropic_aws and gateway on claude-sonnet-4-6.

  10. `/mcp reconnect all` now reconnects every server instead of looking for a server named "all"

    The /mcp argument parser now sends `reconnect all` to a dedicated reconnect-everything flow. That flow reconnects every MCP server that needs it and reports "Reconnected N of M MCP server(s)". If some stay disconnected it adds a hint to run /mcp; in a background session with no terminal attached, the hint says to attach first. If nothing needs reconnecting it says "No MCP servers need reconnecting". Claude Code's own notices already told users to reply "/mcp reconnect all" in the previous build.

  11. Reworded warning when a resumed session holds thinking from another organization Gated

    The warning shown on resuming a session whose thinking came from a different org has been rewritten. It now says the thinking "isn't deleted" and can be used again by resuming signed in to that organization. The old text said it "will be removed". The gate is unchanged: tengu_lexical_glade (fallback false), plus the model's org_locked_thinking capability.

  12. New telemetry when an elicitation-result hook changes the user's answer

    MCP elicitation handling now fires tengu_mcp_elicitation_result_hook whenever an ElicitationResult hook changes the action the user picked. It also tags tengu_mcp_elicitation_response with byHook: true when a hook answered the elicitation. This is added in both the CLI path and the other elicitation path.

  13. Prompt-suggestion back-off now logs start and end events

    The existing back-off (after 20 unused suggestions in a row: "Showing fewer prompt suggestions") now logs prompt_suggestion_back_off_notice when the notice is claimed. It logs prompt_suggestion_back_off_end, with was_notice_claimed and via_config_toggle, when the back-off resets. The thresholds are unchanged: 20 unused, and 14 days (1209600000 ms) since first start. CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION still turns the back-off off.

  14. Account-memory switch command and write-permission dialog wired in but compiled out Gated

    The command list now includes accountMemorySwitch next to memoryAccount. A permission dialog, accountMemoryWritePermissionDialog, is registered for account-memory write tools. The modules backing both are null in this build, so neither is available.

  15. Hidden "How mods work" demo mod: animated Clawd cooking panel over AskUserQuestion, behind tengu_linen_acorn (defaults off) Gated

    New bundled plugin `cc-plugin-mods-guide` hooks `ui.render` for the `AskUserQuestion` component (props `metadataSource: "mod_hot_reload"`). When the question text has a multi-line body, it puts a bold "How mods work" header and an animated pixel-art panel of Clawd stirring a pot above the question card. In the terminal it uses a Raster that it repaints through `ui.blit` on a `clock.every` timer. On other surfaces it uses an SVG. It does not draw when NO_COLOR is set, FORCE_COLOR=0 or TERM=dumb, or when the viewport is too small. It stays still when `prefersReducedMotion` is set.

  16. Hidden `claude plugin marketplace add --from-link` flag for programs that handle install links

    The `plugin marketplace add` command has a new flag, `--from-link`, hidden from `--help`. It adds a marketplace the way an install link does and then prints one JSON line: either the marketplace name with an `added` true/false, or a `refused` object before failing. With the flag set, the reserved-name check is skipped, an already-registered source is reported as `added: false` instead of being added again, and name collisions are refused (`refuseNameCollision`). It can't be combined with `--claudeai`. The string `--from-link` appears only here and in that error message; nothing in the bundle launches the CLI with it, so the caller is an outside program.

  17. Sonnet 5.5 (claude-sonnet-5-5) added and made the default 'sonnet' model

    A new model entry `claude-sonnet-5-5` with display name "Sonnet 5.5" appears in the model catalogue. On first-party it replaces `claude-sonnet-5` as the default for the `sonnet` family and in `latest_per_family`. The model-canonicalisation function checks for `claude-sonnet-5-5` before `claude-sonnet-5`, so the new ID is no longer folded into Sonnet 5. It is also added to the known-models list and gets a Vertex region env var. Third-party per-provider sonnet defaults (bedrock, vertex, foundry, mantle: claude-sonnet-4-5; anthropic_aws, gateway: claude-sonnet-4-6) are unchanged.

  18. Git ownership check now reports why a repository was unvettable

    The safe.directory ownership check used to return a bare false, which produced one fixed message. It now returns a specific reason: git could not run, git exited non-zero (with the exit code), git gave no answer, or git did not name the directory. Those reasons appear in git worktree prune refusals.

  19. Malformed image blocks become a text placeholder instead of throwing

    Each image block in a submitted prompt is now validated before resizing. A missing or non-object `source`, a non-string `media_type`, or undecodable base64 now becomes a text block reading "[Image could not be processed: ...]" instead of throwing. Resize errors of the new error class degrade the same way. `tengu_image_resize_degraded` now carries a `reason` of no_source, malformed_source or resize_error.

  20. Bash command reader follows backslash-newline continuations and refuses more constructs it can't read safely

    The shell-command tokenizer (used to read Bash tool commands) now skips backslash-newline continuations inside operators, redirections, heredoc markers and `$(`/`${` openers via a new `pastContinuations` helper. It also adds new 'unreadable' failure reasons: heredoc delimiters it cannot spell as bash would, empty heredoc delimiters, an ambiguous `{`, and `${…@P}` prompt-expansion. A new `findJoinedLine` matches heredoc terminators that are split across continuation lines.

  21. Status line JSON: gateway spend_limit gains used_usd, limit_usd and period Gated

    On the gateway provider, when an overage limit exists, the status-line payload's `rate_limits.spend_limit` now also carries `used_usd` and `limit_usd` (cents ÷ 100) and an optional `period`. These are filled from a fetched spend record, only when its currency is USD and its reset time matches the overage `resets_at`.

  22. Gateway config validation warns about empty or default-less availableModels

    Gateway config checks add two warnings. First, a managed policy whose `availableModels` is an empty list gets a warning that every request will be rejected. Second, policies whose list leaves out the model Claude Code starts on by default are warned about, unless they set `model`, `enforceAvailableModels`, `availableModelsMatch: "exact"` or `ANTHROPIC_MODEL`/`ANTHROPIC_DEFAULT_MODEL`/`ANTHROPIC_DEFAULT_OPUS_MODEL`: such developers get a 400 until they pick a listed model with /model.

  23. New "Yes, but ask again next time" answer when reading outside the working directories

    The prompt for a read outside the working directories gets a fourth answer, `allow_once`, labelled "Yes, but ask again next time". It allows this one read and sets `askAgainOutsideReads`. That flag skips the step that would otherwise remember a plain "Yes" ("Yes, and keep allowing any reads outside the working directories"). The answer appears in the local dialog as option type `allow-outside-read-once` and in the answer set sent over the bridge. The prompt is opened on auto mode's fallback with reason `outside_read_first_prompt`.

  24. SDK submit_feedback gains save_locally to write a local bundle Gated

    The submit_feedback control request takes a new `save_locally` field. When it is true and no draft_id is given, the report is written as a local bundle and never sent. The response returns the bundle id and `bundle_path`, or a `bundle_write_failed` reason if the write fails. This happens even if the feedback mode has since become 'post' or 'share'; a 'disabled' mode still refuses it. Before, the request went straight to the availability check.

  25. Agent SDK now asks the CLI for session state by default and uses it to decide when a run ends

    Unless the caller already set it (checked case-insensitively), the SDK now sets CLAUDE_CODE_SDK_READS_SESSION_STATE="1" in the spawned CLI's environment. When that variable is set and CLAUDE_CODE_EMIT_SESSION_STATE_EVENTS is not, the CLI emits `session_state_changed` system messages tagged `sdk_host_only: true`. The SDK's Query reader uses them to end the run once the state is idle. It also filters them out, so SDK consumers never see them in their message stream. If a result arrives but the session is not idle and the query has bidirectional needs (SDK MCP servers, hooks, canUseTool, onElicitation…), the SDK arms a ceiling timer and ends the run when it expires. The ceiling comes from CLAUDE_CODE_PRINT_BG_WAIT_CEILING_MS, parsed on the SDK side and falling back to 600000 ms (10 minutes). 0 or less disables it.

  26. Built-in OpenTelemetry hooks module (cc-plugin-otlp), dark-launched Gated

    A new builtin hooks module named "cc-plugin-otlp" registers a `telemetry.log` hook with `to: "collector"`. Records from core or builtin origins are emitted as OTel log records. The engine's telemetry.log and telemetry.mark calls now go through the hooks layer, and records addressed to the collector pass straight through. The module is available only when CLAUDE_CODE_ENABLE_TELEMETRY is truthy and gate tengu_basalt_plover passes, and that gate's compiled fallback is `c = !1`.

  27. Project hooks on remote tools can now run inside the user's own macOS sandbox, behind tengu_violin_saddle (defaults off) Gated

    Remote-tools project hooks decide how to sandbox themselves. When the user already has Claude Code's sandbox or a proxy active on macOS, 2.1.283 simply refused. 2.1.284 adds a "person" mode for that case: the hook command is wrapped with sandbox-exec, using the hook's own read and write lists and a deny-by-default profile, instead of being refused. The mode is only chosen when the new gate XJe() passes. That gate reads tengu_violin_saddle with fallback false, ignores any value whose source is "override", and also needs a second check (IW()) to pass. With no server value, behaviour is unchanged: these hooks still get { unavailable: "person_sandbox" }.

  28. New built-in plugin cc-plugin-mods-guide, behind tengu_linen_acorn (defaults off) Gated

    A new built-in plugin, `cc-plugin-mods-guide`, is registered next to `plugin-authoring`. Its description is "How mods work: asked how hot reloading works, the question card gets a small panel over it with Clawd cooking, gone once the card is answered". Its module includes animation assets (CLAWD_COOKING_SVG, FLAMES, BUBBLES) and uses the `ui.render` hook. It is available only when `tengu_linen_acorn` is on (fallback false, `isOnByDefault` false) and another check, `bh()`, is false. It is not registered when CLAUDE_CODE_ENTRYPOINT is `local-agent`.

  29. PR Steward guidance added to /loop and PR-monitoring prompts (flag, default off) Gated

    There is a new '## PR Steward' prompt section. It tells Claude to check a PR's labels before pushing to it or babysitting it. If the PR carries `claude-pr-steward-watching` or `claude-pr-steward-is-working`, Claude must not push and must not start a loop. It offers the user three choices instead: leave the PR with Steward, make one change and hand back, or take over. In cloud sessions (CLAUDE_CODE_REMOTE) Claude is told never to remove the label itself. The section is added to the /loop skill prompt, the PR-monitoring prompt ('You're monitoring PR #...') and one more prompt builder.

  30. Artifact page guidance allows more script CDNs

    The fallback page contract now lets pages load external scripts from cdnjs.cloudflare.com (preferred), cdn.jsdelivr.net/npm/, unpkg.com, cdn.tailwindcss.com or code.jquery.com. Before, only cdnjs and jsdelivr were allowed.

  31. Max 20x users at a usage limit are pointed to /usage-credits instead of /upgrade

    On the Max plan with rate-limit tier default_claude_max_20x, the limit hint is now "/usage-credits to keep using Claude Code". It appears only when extra usage is off and the usage-credits command is available; otherwise there is no hint. For Pro/Max on the five-hour limit, the "/upgrade to keep using Claude Code" hint no longer shows once extra usage is enabled.

  32. Gateway OIDC supports private_key_jwt certificate client authentication Gated

    In the Claude gateway config, oidc.client_secret becomes optional. A new oidc.client_assertion block (private_key_pem, certificate_pem) works with token_endpoint_auth_method: private_key_jwt. The gateway signs RS256 JWT assertions (x5t thumbprints, 300s expiry) and logs the certificate's thumbprint and expiry. Validation rejects encrypted keys, non-RSA keys, keys under 2048 bits, certificate chains and a certificate that doesn't match the key.

  33. MCP step-up re-auth tells the user a browser is opening

    When an MCP server asks for step-up re-authentication, a non-persisted system message now says the browser is opening. It gives the sign-in URL when that is safe to show, or otherwise points to /mcp.

  34. Remote session event POST reports 'too large' separately

    When POST /events fails because the event is too large, the failure is now tagged `remote_send_event_too_large` and returns `tooLarge: true`, rather than falling under a generic HTTP error.

  35. File sync now says when Anthropic has switched it off

    When the server refuses the synced-file lane with the reason "synced_file_lane_denied", Claude Code now records the cause "switched_off_by_anthropic" instead of the generic lane_unavailable. The user sees a specific message saying file sync was switched off on Anthropic's side, the cloud session keeps whatever files it has, and to re-open the session later. The cause also shows up in paused/refused status states elsewhere in the sync UI.

  36. Plugin marketplace GitHub source match is now case-insensitive

    Two GitHub plugin/marketplace sources are now treated as the same when their `repo` differs only in letter case. Ref and path must still match.

  37. Header cwd display: tengu_violin_maple added as an alternative to tengu_violin_wood Gated

    The welcome/header info that decides how the cwd is shown in remote mode now also switches when tengu_violin_maple is on. Before, only tengu_violin_wood did this.

  38. ScheduleWakeup / loop tool results now tell the model to post a status update and end the turn

    The wakeup tool result now ends with guidance on status updates. 'Nothing more to do this turn' is replaced by 'If you owe the user a status update this tick, … then end the turn'. When this call is the only tool call, the result says 'the turn ends when it returns — there is no post-arm slot for a status update', so the update has to come BEFORE the call. In brief mode, updates must go via the proactive message tool, because plain text is treated as unread. The loop-stopped and max-duration results also append 'Then … — and end the turn.'

  39. ANTHROPIC_FOUNDRY_RESOURCE is validated before building the Azure URL Gated

    The Foundry resource name is only used if it matches the pattern for 2-64 letters, digits or hyphens that do not start or end with a hyphen. Otherwise no `https://<resource>.services.ai.azure.com` URL is derived from it. The runner's inference config schema rejects bad names with the same message.

  40. Remote session config fetch now sends a User-Agent

    The runner's GET `/v1/code/sessions/{id}/remote` request now adds a `User-Agent` header.

  41. SDK submitFeedback can save a /feedback report locally instead of sending it (save_locally) Gated

    The SDK's submitFeedback control request takes a new `save_locally` option. When it is set, the report goes into a redacted zip on the machine and nothing is sent. The response returns `bundle_path`, or `failure_reason: "bundle_write_failed"` if the write fails. Per the schema text, this still applies if the feedback mode has since changed to 'post' or 'share', but a 'disabled' mode still refuses it. The option is ignored when a draft_id is given. Also new: a non-draft submit made before any turn has happened now returns `unavailable_reason` "no turn received yet" instead of carrying on.

  42. Linux sandbox: long bwrap command lines are passed through an unnamed file

    The bwrap sandbox profile builder now checks the size of the command line. It fails with specific errors when there are too many arguments or when a path contains a NUL byte. When the command line is too long, it writes the arguments to an unnamed (O_TMPFILE) file in the temp dir or /dev/shm and hands it to bwrap as `--args` on fd 9 through a `/bin/sh -c exec` wrapper, reading the file via `/proc/<pid>/fd/<n>`. Before this, large sandbox configurations could hit the OS argument-length limit.

  43. Plugin install command confirmation now ignores answers typed too soon after the prompt

    When a plugin is installed by running a command from its marketplace, the interactive "Run this command now?" y/N prompt now goes through a helper that throws away any answer that arrives within 250 ms of the question. It prints "That answer arrived too quickly after the question to count. Please answer again." and asks again, and gives up as declined after more than 5 such early answers. When it re-asks, it first reprints the disclosure text (which command, from which marketplace, and whether it CHANGED since you accepted it). This stops keystrokes typed ahead of the prompt from auto-confirming a shell command.

  44. Browser and computer-use tool schemas can gain an `action_summary` field, behind dark flags Gated

    New code adds an `action_summary` string property to the Chrome `computer`/`form_input` tools, to the `browser_batch` item description, and to computer-use tool schemas. Its description asks the model for a few words on what each action does ("State the effect only, and accurately: no reasons, nothing about what you were asked or allowed to do, no passwords or other secrets."). Two things can switch it on. For Chrome, either `chromeAgentNote === true` in the `tengu_auto_mode_config` remote config, or the `browserSummary` key of the new `tengu_drifting_reef` config object. For computer use, `computerUseAgentNote` or the `computerUseSummary` key of that same object. The first injection logs `chrome_action_summary` / `computeruse_action_summary`. Helpers also count how many expected items actually carried a filled summary.

  45. Sandbox settings reject deny globs that end in a path separator

    Sandbox config validation now flags absolute or `~` glob entries in `filesystem.denyRead`, `filesystem.denyWrite`, and `credentials.files` entries with mode "deny" when they end in a separator, because such a pattern can match nothing. Filesystem sandboxing must not be disabled for the check to run. The message suggests dropping the trailing slash or adding `**`.

  46. Agent hooks in diskless cloud sessions no longer point at a transcript

    Prompt/agent hooks now omit the transcript path when the session is diskless (`launchOptions.diskless()`, i.e. cloud sessions with no disk). The evaluator is told "There is no conversation transcript file to read here; ignore transcript_path in the hook input." The file-index background refresh is also skipped in diskless sessions.

  47. Warm-spare claim timing telemetry

    Claiming a warm spare process now records `spare_claim_token_file_wait_ms` and `spare_claim_apply_ms`.

  48. API error telemetry records whether non-streaming fallback was disabled

    tengu_api_error now includes fallback_disabled, taken from a new nonStreamingFallbackSkipped input.

  49. Tool-result clearing after a long idle (tengu_zany_pike), built but off unless the server sets a mode Gated

    New logic plans a server-side context edit of type clear_tool_uses_20250919 on the first request after the conversation has been idle for at least 3900 seconds and holds at least 20 clearable tool uses. It keeps the last 5 tool uses. The mode is read from the "tengu_zany_pike" gate, which accepts "on", "shadow" or "off". If the value comes from the fallback, the mode becomes "unknown": no new clearing is planned, and planning only continues where earlier messages show the server already cleared tool results. "shadow" only logs telemetry and sends no edit. The planner is called from the main request builder.

  50. Prompt suggestions no longer take text from API error messages

    When the prompt-suggestion fork collects assistant text, it now skips messages flagged isApiErrorMessage. An API error string can therefore no longer be offered as a suggested next prompt.

Claude Code v2.1.284

next 1 entry read v2.1.283 → v2.1.284 Mods API: +22 added · 0 removed · 7 changed · 12 docs only Markdown JSON Follow Unofficial

A first look at v2.1.284, written minutes after it reached npm from a quick read of the bundle. It is thin on purpose and some of it will turn out to be wrong. The full changelog replaces this page when the deep run finishes.

Written by our agent from the shipped bundle, not by Anthropic.

Want the reasoning? Read walks every section of this release, each entry opening to what changed and why.

Read this release → Every row →
Pick an entry · j / k steps through · rest on a row to peek
1 entry

First read of the bundleopen

Verbatim
Awaiting notes

Official release notes pending

Anthropic has not published official notes for v2.1.284 yet. This section updates automatically when the entry appears in the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.

System prompt

1 added and 1 removed, of 218 lines, about 4 words, in the prompt 15 of 27 arms receive. 3 other prompts also changed. 1 of 27 tool descriptions changed. The appended system-reminder blocks moved: 1 line added.

Claude Code, interactive mode

Documentation

What the docs did around this release

57 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.

Feedback