Claude Code

Claude Code 2.1.289: agent.spawn for Teammates, and Four Holes in the Permission Rules

2 min read AI-generated

An rm -rf with an environment variable in front of it slipped past a deny rule under sandbox auto-allow. Of 27 changelog lines, exactly one starts with Added.

Featured image for "Claude Code 2.1.289: agent.spawn for Teammates, and Four Holes in the Permission Rules"

2.1.289 landed in the npm registry on October 3 at 20:12 UTC. Twenty-seven changelog lines: 23 fixes, two improvements, one revert, and exactly one new thing. This is the cleanup release behind 2.1.287, the mods release, and behind 2.1.288.

Four holes in the permission rules

The most important lines are the ones nobody writes about. Four ways deny and ask rules failed to hold:

  • An environment variable in front of a command hid it, when the sandbox auto-allows commands. The changelog’s example is an rm -rf build with a TZ value in front of it.
  • The same thing with a bare variable assignment before the command.
  • A deny or ask rule on a nested part of a compound shell command didn’t hold against a user-installed mod’s approval on managed machines.
  • Read deny rules didn’t apply to files that arrived through a symlink via @-mention, a change, or an IDE selection.

Plus a fifth line of the same kind: a user-installed plugin could rewrite the descriptions of an organization-managed MCP server’s sign-in tools. If you take permission rules seriously, don’t sit on this update.

What’s new

agent.spawn for teammates. Alongside it, plugin hook events now carry one agent id across all events, and $.agent.list() reports idle and waiting states. So mods can start agents themselves instead of only watching them, and follow one across its lifetime.

What else got cleaned up

The terminal froze on short code blocks with many unclosed <script> tags or deeply nested ${ substitutions — the same bug also took down the reader’s browser tab on published artifact pages. Installed mods didn’t load in the first session after an upgrade. A mod’s Client that failed while drawing took everything the mod had drawn around it down with it; now it fails alone and raises ui.fault. And in VS Code, Anthropic reverted a 2.1.288 change to claude auth status that may have made sign-outs more frequent.

The mods cost a week

Since 2.1.287, three releases in a row have been almost entirely about mods. Not about new capabilities, but about making sure a broken mod no longer takes the session with it: now it falls over alone, names itself to its author, and leaves the terminal standing.

That’s the bill for letting third-party code into the draw loop. It’s probably the right bill to pay — but four missed ways around a deny rule in a single release says the permission layer has grown past the point where you can check it in your head.

Sources:

Claude CodeAnthropicReleasesPluginsSicherheit