You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Keyword counts on excerpt: Hook:9 Skill:6 Agent:26 Permission:14 Plugin:29 MCP:19 Sandbox:5 Breaking:1 Deprecation:14 Deprecated identifiers still referenced in repo code:TaskOutput, taskOutputMaxChars, TASK_MAX_OUTPUT_LENGTH (the pre-computed list handed to this run was empty — see below) Upstream changelog:https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md
Deprecations referenced in our code (highest priority)
TaskOutput tool — REMOVED in 2.1.278. Replacement: Claude reads a background task's output file with Read. The taskOutputMaxChars setting and TASK_MAX_OUTPUT_LENGTH env var no longer have any effect. This is exactly the claude-plugins#1638 miss class, and the automated detector handed this run an empty deprecated-identifier list even though the identifier is live in our tree. Referencing files found by grep:
.claude/rules/agent-development.md
agent-patterns-plugin/skills/agent-teams/SKILL.md (lists TaskOutput among the native team tools)
Intentional/self-referential (leave alone unless the detection list needs the string): project-plugin/skills/changelog-review/**, .claude/rules/regression-testing.md, CHANGELOGs
Secondary: 2.1.276 fixed /update-config writing Write(path) permission rules "which file permission checks don't match" — confirms the 2.1.210 Write(path)/NotebookEdit(path)/Glob(path) deprecation already tracked in Review Claude Code changelog: 2.1.185 → 2.1.215 #2623. Audit any skill that emits Write(...) permission rules.
Follow-up tasks
For each file below, the listed bullets are the relevant changes from the excerpt. To address: @claude please update <file> for the bullets listed in this issue.
.claude/rules/agent-development.md
HIGH/REMOVAL (2.1.278):TaskOutput tool removed; background task output is read with Read. taskOutputMaxChars / TASK_MAX_OUTPUT_LENGTH are inert.
HIGH (2.1.278): subagent results now reach the main agent under a header marking them as subagent output, with the result indented, so text in a subagent's result cannot pass as the session's own instructions. Worth documenting as a prompt-injection boundary in the parallel-dispatch/teams guidance.
(2.1.278) Fixed messages from other agents (subagent SendMessage) arriving mid-turn rendering in the wrong place.
(2.1.278) Fixed resumed subagents/teammates re-rendering their MCP tool definitions, which broke prompt caching for that agent.
(2.1.274) Fixed subagents with model: "opus" on Bedrock/Vertex/Foundry leaving the session model when the id has no recognizable family (unless ANTHROPIC_DEFAULT_OPUS_MODEL is set).
(2.1.274) Improved safety checks before removing an agent worktree containing submodule checkouts — relevant to .claude/rules/agent-coworker-detection.md § worktree cleanup.
(2.1.274) Fixed claude agents losing --model, --effort, --permission-mode, --allow-dangerously-skip-permissions, --agent after an auto-update relaunch.
(2.1.274) Fixed a resumed background agent keeping half of an interrupted tool batch; plus background-agent notification fixes.
.claude/rules/hooks-reference.md
(2.1.276) SubagentStop hooks with a specific matcher were firing for every stopping subagent whose agent type was empty — fixed. Matcher-semantics note.
(2.1.278) Fixed sessions continued after /clear (restart, --continue, --resume) missing part of their first message when a SessionStart hook printed output, causing a full prompt-cache miss.
(2.1.278) Fixed a crash resuming a session whose transcript contains a stop-hook summary without a well-formed hook list.
(2.1.274) Fixed hook-driven sessions (e.g. an active /goal) ending with "Prompt is too long" instead of compacting; an active /goal was lost on --continue/--resume after compaction. Relevant to .claude/rules/loop-integrity.md.
(2.1.274) Plugins with a top-level $schema in hooks/hooks.json no longer show an "unknown key" notice.
.claude/rules/prompt-agent-hooks.md
(2.1.274) Stop prompt hooks no longer re-send their whole prompt on every block; repeat blocks now name the condition with a 500-character label. Document the truncation budget.
.claude/rules/agentic-permissions.md
(2.1.274) Bash permission checks for commands that loop over or assign certain special shell variables now ask for permission (previously auto-approved).
(2.1.274) Worktree-isolated sessions now refuse Bash commands with certain nested shell expansions.
(2.1.276) /update-config no longer writes Write(path) rules (file permission checks don't match them) — it writes Edit(path). Reinforces the 2.1.210 deprecation; audit our permission-rule guidance and any skill that emits rules.
(2.1.278) The dangerous-rm permission prompt now names the flagged command and suggests a ${VAR:?} guard so headless runs can recover.
(2.1.278) Fixed the Write tool silently ending the turn as a declined permission when the target path is an existing directory; now a clear error.
HIGH (2.1.278): auto mode for Claude API and Enterprise users, and on Bedrock/Vertex/Foundry/gateways, now defaults to the server-side classifier, which does not charge for classifier overhead. CLAUDE_CODE_AUTO_MODE_SERVER=0 opts out on Bedrock/Vertex/Foundry/gateways; a billed fallback warns. New Auto mode server row in /status. Docs: https://code.claude.com/docs/en/auto-mode-classifier-billing
(2.1.276) Claude in Chrome in auto mode skips the extension's per-site check for classifier-approved calls (as bypass mode does).
.claude/rules/skill-development.md
(2.1.278) Fixed project skills from the main repository not loading in --worktree sessions when .claude/skills is untracked — directly affects this repo's worktree-based agent dispatch.
(2.1.278) Fixed /plugin → Installed and /skills crashing when a skill or legacy command is named like a built-in Object property (constructor, toString) — a real naming constraint worth a line in .claude/rules/skill-naming.md.
(2.1.275) Added syncing of claude.ai-account skills/plugins to terminal sessions; opt out with syncClaudeAiSkills: false / syncClaudeAiPlugins: false. (2.1.276) Write/Edit results for files in the synced account-skills folder now say the change is not saved to your account.
(2.1.275) Fixed --forward-subagent-text stream-json/SDK output dropping messages of subagents spawned by a context: fork skill — also .claude/rules/skill-fork-context.md.
.claude/rules/plugin-structure.md
(2.1.276) Plugins installed from an npm source are now fetched with npm pack --ignore-scripts and integrity-verified — a package's install scripts no longer run.
(2.1.278) claude plugin install no longer breaks the installed copy when reinstalling a version another session is using; it also now reports when the marketplace offers a newer version and names claude plugin update.
(2.1.278) Fixed plugins from the official marketplace being recorded without their commit in installed_plugins.json, and the file keeping the old commit after updating a pinned-commit plugin.
(2.1.278) Fixed one malformed strictKnownMarketplaces / blockedMarketplaces entry silently disabling the whole enterprise marketplace policy — fail-open hazard worth noting.
(2.1.278) Fixed uninstalled plugins reappearing as "failed to load" rows; /plugin now strips terminal control characters from Installed-tab messages.
(2.1.275) Added /plugin install <plugin> --marketplace <source>, which offers to add the marketplace first. Fixed claude plugin marketplace update deleting a GitHub marketplace's local copy on fetch failure; plugin/marketplace logs no longer leak tokens stored in git/ssh/marketplace URLs.
(2.1.274) Fixed a plugin/marketplace directory with no git repo of its own taking its version from an enclosing git repo (e.g. a git-managed ~/.claude); installed_plugins.json no longer rewritten on nearly every start-up under remote managed settings.
(2.1.274) Plugin and marketplace clones now leave Git LFS files as pointers; git lfs pull in the checkout fetches them.
.claude/rules/sandbox-guidance.md
HIGH (2.1.278): a sandbox.excludedCommands glob no longer exempts an entire compound Bash command when only one part matched — every part must now match. Behaviour change for any excludedCommands config we recommend.
(2.1.278) Fixed $TMPDIR expanding empty in Bash commands that run outside the sandbox while sandboxing is enabled.
(2.1.276) Fixed sandboxed Bash commands on Linux reporting exit code 0 for failed commands when the shell is zsh — cross-ref tools-plugin:zsh-gotchas.
(2.1.276) Fixed sandboxed Bash commands being unable to write to project directories named hooks/ or config/.
(2.1.278) Fixed WebFetch/WebSearch in Cowork cloud sessions not reporting why a request was refused (used-up fetch budget, admin policy).
HIGH (2.1.277):AGENTS.md support — in a project with no CLAUDE.md, Claude Code reads AGENTS.md instead; configurable under "Project instructions" in /config (not yet on Bedrock/Vertex/Foundry). Affects onboarding skills (configure-plugin:configure-repo) and any guidance assuming CLAUDE.md is the only project-instruction file.
HIGH/MCP (2.1.274): Bedrock, Vertex, Foundry and telemetry-disabled installs now use the v2 MCP client and MCP 2026-07-28 negotiation with direct HTTP servers by default (opt out: MCP_SDK_GENERATION=v1 or MCP_PROTOCOL_NEGOTIATION=legacy).
HIGH/MCP (2.1.274):"type": "sdk" MCP entries in .mcp.json, settings, plugins and agent files are now skipped with a warning — only an SDK host application can register in-process servers.
(2.1.274) New CLAUDE_CODE_MCP_STARTUP_WAIT_MS bounds how long the first non-interactive turn waits for connecting MCP servers (0 = don't wait); --strict-mcp-config with an empty --mcp-config no longer holds the first turn for MCP_TIMEOUT.
(2.1.274) MCP fixes: http servers speaking only legacy HTTP+SSE now connect after a 4xx on the first request; Streamable HTTP tool calls honour a longer per-server timeout (previously capped ~5 min); list-changed refresh without a declared listChanged; 403 insufficient_scope now names missing permissions and points at /mcp re-auth; MCP connection errors no longer print secrets resolved from ${VAR}.
(2.1.278) /plugin Installed now shows which plugin an MCP server belongs to.
(2.1.274/2.1.275) OTel additions for instrumentation skills: effort on claude_code.llm_request, new claude_code.managed_settings_resolved event (OTEL_LOG_MANAGED_SETTINGS=1), OTEL_LOG_RAW_API_BODIESindex.jsonl linkage, and a startup warning when otelHeadersHelper fails.
(2.1.278) Workflow scripts' computed agent() prompts on Bedrock/Vertex/Foundry now reach the subagent framed as script-authored text, so the safety classifier does not read them as the user.
(2.1.274) /code-review now uses leaner inline review prompts for every model that has no tuned settings of its own, instead of spawning many review subagents.
(2.1.278) /ultrareview improvements: clearer "nothing to review" messaging, reviews a new repository's first commit in full, and refuses in non-interactive sessions when the repo has no base branch or shared history. Affects the /code-review ultra guidance in this repo's session instructions.
Low / no action (recorded for completeness)
2.1.276 is a single-line regression fix for ANTHROPIC_BASE_URL proxies. The bulk of 2.1.274–2.1.278 is VS Code, Claude Tag, Claude Code on the web, TUI rendering and crash fixes — no rule impact.
Triage of upstream changelog 2.1.273 → 2.1.278.
Keyword counts on excerpt: Hook:9 Skill:6 Agent:26 Permission:14 Plugin:29 MCP:19 Sandbox:5 Breaking:1 Deprecation:14
Deprecated identifiers still referenced in repo code:
TaskOutput,taskOutputMaxChars,TASK_MAX_OUTPUT_LENGTH(the pre-computed list handed to this run was empty — see below)Upstream changelog: https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md
Deprecations referenced in our code (highest priority)
TaskOutputtool — REMOVED in 2.1.278. Replacement: Claude reads a background task's output file withRead. ThetaskOutputMaxCharssetting andTASK_MAX_OUTPUT_LENGTHenv var no longer have any effect. This is exactly the claude-plugins#1638 miss class, and the automated detector handed this run an empty deprecated-identifier list even though the identifier is live in our tree. Referencing files found by grep:.claude/rules/agent-development.mdagent-patterns-plugin/skills/agent-teams/SKILL.md(listsTaskOutputamong the native team tools)hooks-plugin/hooks/bash-antipatterns.sh+hooks-plugin/hooks/test-bash-antipatterns.sh(the changelog-review: blind to tool deprecations + skip-if-exists silently suppresses an unactioned backlog #1638 file — re-verify)agents-plugin/agents/debug.md,agents-plugin/agents/test.mdscripts/export-pi-agents.py+scripts/tests/test-export-pi-agents.shdocs/pi-export.mdproject-plugin/skills/changelog-review/**,.claude/rules/regression-testing.md, CHANGELOGs/update-configwritingWrite(path)permission rules "which file permission checks don't match" — confirms the 2.1.210Write(path)/NotebookEdit(path)/Glob(path)deprecation already tracked in Review Claude Code changelog: 2.1.185 → 2.1.215 #2623. Audit any skill that emitsWrite(...)permission rules.Follow-up tasks
For each file below, the listed bullets are the relevant changes from the excerpt. To address:
@claude please update <file> for the bullets listed in this issue..claude/rules/agent-development.md
TaskOutputtool removed; background task output is read withRead.taskOutputMaxChars/TASK_MAX_OUTPUT_LENGTHare inert.SendMessage) arriving mid-turn rendering in the wrong place.model: "opus"on Bedrock/Vertex/Foundry leaving the session model when the id has no recognizable family (unlessANTHROPIC_DEFAULT_OPUS_MODELis set)..claude/rules/agent-coworker-detection.md§ worktree cleanup.claude agentslosing--model,--effort,--permission-mode,--allow-dangerously-skip-permissions,--agentafter an auto-update relaunch..claude/rules/hooks-reference.md
SubagentStophooks with a specificmatcherwere firing for every stopping subagent whose agent type was empty — fixed. Matcher-semantics note./clear(restart,--continue,--resume) missing part of their first message when a SessionStart hook printed output, causing a full prompt-cache miss./goal) ending with "Prompt is too long" instead of compacting; an active/goalwas lost on--continue/--resumeafter compaction. Relevant to.claude/rules/loop-integrity.md.$schemainhooks/hooks.jsonno longer show an "unknown key" notice..claude/rules/prompt-agent-hooks.md
.claude/rules/agentic-permissions.md
/update-configno longer writesWrite(path)rules (file permission checks don't match them) — it writesEdit(path). Reinforces the 2.1.210 deprecation; audit our permission-rule guidance and any skill that emits rules.rmpermission prompt now names the flagged command and suggests a${VAR:?}guard so headless runs can recover..claude/rules/auto-mode.md (repo-designated addition)
CLAUDE_CODE_AUTO_MODE_SERVER=0opts out on Bedrock/Vertex/Foundry/gateways; a billed fallback warns. NewAuto mode serverrow in/status. Docs: https://code.claude.com/docs/en/auto-mode-classifier-billing.claude/rules/skill-development.md
--worktreesessions when.claude/skillsis untracked — directly affects this repo's worktree-based agent dispatch./plugin→ Installed and/skillscrashing when a skill or legacy command is named like a built-in Object property (constructor,toString) — a real naming constraint worth a line in.claude/rules/skill-naming.md.syncClaudeAiSkills: false/syncClaudeAiPlugins: false. (2.1.276) Write/Edit results for files in the synced account-skills folder now say the change is not saved to your account.--forward-subagent-textstream-json/SDK output dropping messages of subagents spawned by acontext: forkskill — also.claude/rules/skill-fork-context.md..claude/rules/plugin-structure.md
npm pack --ignore-scriptsand integrity-verified — a package's install scripts no longer run.claude plugin installno longer breaks the installed copy when reinstalling a version another session is using; it also now reports when the marketplace offers a newer version and namesclaude plugin update.installed_plugins.json, and the file keeping the old commit after updating a pinned-commit plugin.strictKnownMarketplaces/blockedMarketplacesentry silently disabling the whole enterprise marketplace policy — fail-open hazard worth noting./pluginnow strips terminal control characters from Installed-tab messages./plugin install <plugin> --marketplace <source>, which offers to add the marketplace first. Fixedclaude plugin marketplace updatedeleting a GitHub marketplace's local copy on fetch failure; plugin/marketplace logs no longer leak tokens stored in git/ssh/marketplace URLs.~/.claude);installed_plugins.jsonno longer rewritten on nearly every start-up under remote managed settings.git lfs pullin the checkout fetches them..claude/rules/sandbox-guidance.md
sandbox.excludedCommandsglob no longer exempts an entire compound Bash command when only one part matched — every part must now match. Behaviour change for any excludedCommands config we recommend.$TMPDIRexpanding empty in Bash commands that run outside the sandbox while sandboxing is enabled.tools-plugin:zsh-gotchas.hooks/orconfig/.CLAUDE.md (and MCP-facing skills:
configure-plugin:configure-mcp,agent-patterns-plugin:mcp-management)AGENTS.mdinstead; configurable under "Project instructions" in/config(not yet on Bedrock/Vertex/Foundry). Affects onboarding skills (configure-plugin:configure-repo) and any guidance assuming CLAUDE.md is the only project-instruction file.MCP_SDK_GENERATION=v1orMCP_PROTOCOL_NEGOTIATION=legacy)."type": "sdk"MCP entries in.mcp.json, settings, plugins and agent files are now skipped with a warning — only an SDK host application can register in-process servers.CLAUDE_CODE_MCP_STARTUP_WAIT_MSbounds how long the first non-interactive turn waits for connecting MCP servers (0= don't wait);--strict-mcp-configwith an empty--mcp-configno longer holds the first turn forMCP_TIMEOUT.httpservers speaking only legacy HTTP+SSE now connect after a 4xx on the first request; Streamable HTTP tool calls honour a longer per-servertimeout(previously capped ~5 min); list-changed refresh without a declaredlistChanged; 403insufficient_scopenow names missing permissions and points at/mcpre-auth; MCP connection errors no longer print secrets resolved from${VAR}./pluginInstalled now shows which plugin an MCP server belongs to.effortonclaude_code.llm_request, newclaude_code.managed_settings_resolvedevent (OTEL_LOG_MANAGED_SETTINGS=1),OTEL_LOG_RAW_API_BODIESindex.jsonllinkage, and a startup warning whenotelHeadersHelperfails.Workflow / code-review guidance (
.claude/rules/workflow-model-effort.md, code-review skills)agent()prompts on Bedrock/Vertex/Foundry now reach the subagent framed as script-authored text, so the safety classifier does not read them as the user./code-reviewnow uses leaner inline review prompts for every model that has no tuned settings of its own, instead of spawning many review subagents./ultrareviewimprovements: clearer "nothing to review" messaging, reviews a new repository's first commit in full, and refuses in non-interactive sessions when the repo has no base branch or shared history. Affects the/code-review ultraguidance in this repo's session instructions.Low / no action (recorded for completeness)
2.1.276 is a single-line regression fix for
ANTHROPIC_BASE_URLproxies. The bulk of 2.1.274–2.1.278 is VS Code, Claude Tag, Claude Code on the web, TUI rendering and crash fixes — no rule impact.🤖 Triaged with Claude Code