█

AI/TLDR

Anthropic · 2026-10-03 · major

Claude Code 2.1.289 — deny rules now catch env-prefixed shell commands

Claude Code 2.1.289 closes gaps where Bash deny and ask rules could be skipped, for example behind an environment variable prefix under sandbox auto-allow. It also adds agent.spawn for plugin teammates and fixes many mod and plugin crashes.

Claude Code repository card on GitHub

Claude Code tightens its shell permission rules and makes plugins and mods fail alone instead of ending the session.

Quick facts

Versionv2.1.289
MakerAnthropic
Released2026-10-03
SecurityBash deny/ask rules hold behind env-var prefixes and assignments
New for pluginsagent.spawn for teammates, idle/waiting states in $.agent.list()
VS CodeReverts a 2.1.288 claude auth status change

What is it?

Bash deny and ask rules in Claude Code 2.1.289 no longer miss a command hidden behind an environment variable prefix with an expanded value, such as TZ="$HOME" rm -rf build, or behind a bare variable assignment, when the sandbox auto-allows commands. Read deny rules now also apply to files reached through a symlink from the IDE.

How does it work?

Most of the release hardens the plugin and mod system. A mod's Client that throws while drawn now fails alone and raises ui.fault, and the engine draws its own row when a ui.render value would crash it, instead of ending the session with an interface error. A user-installed plugin can no longer rewrite the descriptions of an organization-managed MCP server's sign-in tools.

Why does it matter?

Teams that rely on deny rules to block destructive commands get rules that hold in more of the shell forms an agent might write. Plugin authors gain agent.spawn for teammates and one agent id across hook events, and users of mods should see far fewer sessions killed by a single broken extension.

Who is it for?

Claude Code users, admins of managed machines, plugin and mod authors

Frequently asked questions

Which permission bypasses does Claude Code 2.1.289 fix?
Claude Code 2.1.289 fixes Bash deny and ask rules missing a command behind an environment variable prefix with an expanded value, like TZ="$HOME" rm -rf build, and being skipped when a bare variable assignment came first, both under sandbox auto-allow. It also makes a deny or ask rule on a nested part of a compound command hold over a user-installed mod's approval on managed machines.
What changes for Claude Code plugin authors in 2.1.289?
Claude Code 2.1.289 adds agent.spawn for teammates, one agent id across plugin hook events, and idle and waiting states in $.agent.list(). It also fixes plugin list, plugin eval and plugin update showing a stale copy of a plugin from a local folder marketplace, and hot reload for a symlinked --plugin-dir.
Does Claude Code 2.1.289 fix sign-out problems in VS Code?
Claude Code 2.1.289 reverts a change made in 2.1.288 to claude auth status in the VS Code extension. Anthropic's release notes say that earlier change may have made sign-outs more frequent, so updating to 2.1.289 restores the previous behavior for VS Code users.
Can a broken mod still crash a Claude Code session after 2.1.289?
Claude Code 2.1.289 fixes several ways a mod could end a session: an asynchronous throw in an on-screen handler, a plugin region with no height that kept growing, and a ui.render value that made a row throw. A failing mod Client now fails alone and raises ui.fault, and the error line names the mod.

Try it

npm i -g @anthropic-ai/claude-code@2.1.289

Sources · 2 outlets

Tags

  • claude-code
  • anthropic
  • coding-agent
  • cli
  • permissions
  • security
  • plugins
  • claude-mods
  • developer-tools
  • release

← All releases · Learn AI