Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.295 ·

A new setting limits what your own skills, agents and hooks can do

Setting CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG stops your own skills, agents and hooks from widening permissions, and makes key hooks required

Use it now Notable No documentation found New Features
JSON All of v2.1.295
Use it nowTier: how much it should matter to you
5Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
SettingsArea: what it touches
New FeaturesKind: in v2.1.295,
What probably matters to youSection of the release
What

CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG is an environment variable, a named value set before Claude Code starts. It can also be set in the env section of a settings file. When it is set, files you wrote yourself, such as your own skills, agents and hooks, cannot widen what Claude may do in the session:

  • Your own skills and commands cannot pre-approve tools with allowed-tools.
  • Your own agents (helpers Claude can hand work to) cannot define MCP servers or widen their permission mode.
  • A WorktreeCreate hook from your own files cannot choose the folder for the worktree, the separate working copy Claude Code makes.
  • Some fields in the output of your own hooks are dropped, and a note is logged.
  • Plugins kept inside your own skills folder load only as skills.
  • Launching a cloud agent is refused, with a message saying to set isolation to "worktree".
  • Hooks that carry files you uploaded to claude.ai are refused for hooks that run inside Claude Code itself.

Hooks are actions you set up to run at set points. While this variable is set, your own command and HTTP hooks on PreToolUse, PermissionRequest, PreModelSwitch, UserPromptSubmit and UserPromptExpansion must succeed. If one fails or times out, the action is blocked, and the message tells you to fix or remove the hook and tells Claude not to change it. Each restriction logs a message that names the variable. The variable is also passed on to programs Claude Code starts.

Separately, a command or HTTP hook can now set onFailure to "block", so that its failure or time-out blocks the action, except on events that run when Claude stops.

Why

This makes a locked-down session where files in your own Claude Code folder cannot grant extra permissions or quietly fail to run a check. It fits places where Claude Code runs under someone else's control and a user's own settings should not override theirs.

Read from
How sure we are
Two sources agreeTwo things we can check say the same as this entry.
Anthropic's release notes agreeFixed a skill's allowed-tools and effort being dropped when the Skill tool finished before the response stream ended, which denied the…
The name it cites is new in this buildNew in this build: CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG

See this entry in the whole of v2.1.295 →

Feedback