Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.287 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.288 ·

Frontmatter from MCP, memory stores and plugins is read as untrusted

Skills from MCP servers and memory stores, and plugin agents, now have their frontmatter read with limits and are skipped or refused if it can't be read

Group of 2 You'll notice Improvements
JSON All of v2.1.288
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
ElsewhereArea: what it touches
ImprovementsKind: in v2.1.288,
ImprovementsSection of the release

What

Frontmatter is the settings block at the top of a skill or agent file, between two --- lines. Skills are reusable instructions Claude can load, and agents are helpers with their own instructions. The frontmatter reader now has an untrusted option. When it is set, the reader refuses frontmatter that is too long, too nested, or may hold a YAML anchor (a shortcut that repeats one part of the file elsewhere), and reports a parse error.

  • Skills from MCP servers are read with untrusted: true. If the frontmatter is refused, the skill is skipped and a message says the frontmatter was not read and the skill was skipped.
  • Skills from memory stores are read with untrusted: true. If the frontmatter is refused, the skill is skipped and the log says frontmatter was not read.
  • Plugin agents are read with untrusted, and loading fails with an error if the frontmatter is refused. Before, plugin agent frontmatter was read without limits.
  • The reader also skips its pattern match when there is no second --- line.

Why

Skills and agents from remote MCP servers, shared memory stores and plugins come from outside your own setup. Oversized or malformed frontmatter from them is now refused instead of loaded, so a skill or agent may stop appearing if its frontmatter breaks these limits.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear what reading a header as untrusted changes beyond skipping skills whose header fails.

See this entry in the whole of v2.1.288 →

Feedback