Claude Code

Claude Code 2.1.288: --max-findings for /code-review, and a Prompt Cleared With Ctrl+C Comes Back

3 min read AI-generated

A dangerous rm — on / or the home directory — ran without a prompt inside a bash -c script under bypassPermissions. The same class of hole was in 2.1.287 the day before, in a different shape.

Featured image for "Claude Code 2.1.288: --max-findings for /code-review, and a Prompt Cleared With Ctrl+C Comes Back"

Version 2.1.288 landed in the npm registry on October 2 at 18:30 UTC. The changelog is long, and most lines start with “Fixed.” 2.1.287, from the day before, was the mods release; this one cleans up behind it and adds three things you’ll notice in daily use.

The prompt you just threw away

Press Ctrl+C, the prompt empties, then press Up — and your draft is back, pasted text and images included. One small line that will probably please more people than anything else in this release.

Two more keyboard lines go with it: Ctrl+F finds a session by name, and Alt+↑/↓ jumps between groups in the agents view. Both, and rename, can be rebound in keybindings.json.

/code-review gets its own ceiling

--max-findings <n>|all reports more or fewer findings than the usual limit, and the choice sticks until you pass --max-findings default. If you’ve ever abandoned a review because the list stopped at ten and the interesting ones came after, you know why.

Mod authors get $.ui.selection(): the text you last selected in fullscreen mode, plus the transcript row when the selection sits inside one.

Failures mid-response

The most important repair concerns sessions nobody is watching. API timeouts arriving mid-response used to fail the turn; non-interactive sessions and subagents now continue from the partial response, and thinking-only responses get retried. Alongside that:

  • Long conversations failed with “Prompt is too long” instead of auto-compacting when the last reply reported zero token usage.
  • --resume sometimes dropped files and other context that a compaction had just restored.
  • A resumed session occasionally didn’t save a turn’s last response, so the next --resume showed the prompt unanswered.
  • Resuming a conversation started on 2.1.286 or earlier dropped the model’s earlier thinking.
  • Unattended sessions using CLAUDE_CODE_RETRY_WATCHDOG kept retrying for hours after a very long response stream failed. Claude Code now streams again and gives up after three timeouts.

Two security lines that belong together

A dangerous rm — on / or the home directory, say — ran without a prompt inside a bash -c or sh -c script, in bypassPermissions mode or under a shell allow rule. 2.1.287 carried a line of the same class: there, the same rm lost its always-ask safeguard when the command also redirected output to a ~ or wildcard path.

Two hook lines go with it. PreToolUse and PermissionRequest hooks were skipped when matching them failed or the tool’s input couldn’t be serialized to JSON — the call is now blocked instead of waved through. And the Bash tool’s permission check now prompts before a BASHPID assignment whose value the shell would evaluate as arithmetic.

For plugin and mod authors

Seven lines concern plugins. A plugin’s tool.call hook made Bash fail and file searches read the wrong folder in subagents running in a worktree. git-subdir installs failed on git older than 2.39, Ubuntu 22.04’s for instance. Plugin LSP servers received literal ${user_config.*} and ${CLAUDE_PLUGIN_ROOT} placeholders in initializationOptions and settings rather than substituted values. And background sessions ended when a plugin was reloaded or disabled while one of its timers was still running.

A release that cleans up after mods week

The distribution is the interesting part. A feature release on October 1, and a day later four dozen fixes, many of them in the mod and plugin surface that only opened the day before. That’s the price of putting an extension point that deep: every place a mod may intervene is also a place something can break.

The two rm lines on consecutive days say the same thing from the other side. The safeguard exists, and it hung on the exact shape of the command. Anyone running bypassPermissions should read that as a reminder that the mode means what it says.

Sources:

Claude CodeAnthropicReleasesPluginsSicherheit