Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.287 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.287 ·

Plugin hook modules run in a stricter sandbox

Plugin hook modules can no longer use dynamic import or export then, and more unsafe values are refused

You'll notice Improvements
JSON All of v2.1.287
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
HooksArea: what it touches
ImprovementsKind: in v2.1.287,
ImprovementsSection of the release
What

Plugins can include hook modules: code that runs in a sandbox, a walled-off space kept apart from the rest of Claude Code. That sandbox now refuses more things:

  • Dynamic import() inside a hooks module is refused.
  • An entry module that exports the name then is rejected and must rename the export.
  • Values passed back to Claude Code cannot behave like promises (deferred results).
  • Lists claiming an absurd length are rejected.
  • Drawn screen elements that contain a Proxy (an object that intercepts access) are refused.
  • Errors passing out of the sandbox are converted to a fallback error.
Why

The sandbox is tighter, so plugin hook authors may now see load errors for modules that used to work and need to adjust them.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear whether plugin hook modules are switched on for every user.

See this entry in the whole of v2.1.287 →

Feedback