Follow Discord
Sweep 03 Oct 2026 · 20:28Z Build v2.1.289 510 read Stable v2.1.285 Latest v2.1.289 Next v2.1.289 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.289 ·

Values leaving the plugin hook sandbox are now copied and checked

Plugin hook values leaving the plugin's sandbox are now copied, frozen and checked as plain data, unless isLeavingUncopied is set

Group of 2 Under the hood Internal Changes
JSON All of v2.1.289
Under the hoodTier: how much it should matter to you
2Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
Plugin HooksArea: what it touches
Internal ChangesKind: in v2.1.289,
Internal ChangesSection of the release

What

Plugin hooks run in a sandbox, a walled-off space kept apart from Claude Code itself. Values passing out of that space were passed through vmClone only. They are now copied and checked first.

  • Copying: values leaving the plugin environment are copied and frozen so they can't be changed afterwards. Records, arrays, maps, errors and other values are walked and copied.
  • Refused values: functions, Proxies and unknown kinds are refused. Arguments that are not plain data are rejected with a message of the form "not plain data".
  • Switch: copying is skipped when the host option isLeavingUncopied is set. That option is turned on when a separate internal check returns false, which suggests the change is being rolled out in stages.

Why

This hardens the boundary between plugins and Claude Code. Plugin authors should watch for it: a hook that returns functions or other non-plain values may now have them refused.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear what sets the option that lets values leave the sandbox uncopied.

See this entry in the whole of v2.1.289 →

Feedback