Claude Code

Claude Code 2.1.292 gives subagents an effort parameter and closes a hole on network paths

4 min read AI-generated

A skill with an overlong description could wipe every skill stored on the machine. Past 1,024 characters the desktop app now refuses it, and says why.

Featured image for "Claude Code 2.1.292 gives subagents an effort parameter and closes a hole on network paths"

Two versions in one day. 2.1.291 hit the npm registry on October 6 at 03:32 UTC and consists of two lines: a regression from 2.1.290 where cloud sessions could drop answers to permission prompts, and one from 2.1.288 where the last messages of a session could be lost on quit.

2.1.292 arrived the same evening at 17:10 UTC, and that’s the big one.

Subagents now run at the effort you set

The Agent tool takes an effort parameter. You decide per subagent how much effort it runs with instead of taking what you get. If you run several agents in parallel, that’s the most useful line in the changelog.

Alongside it: --marketplace <source> for claude plugin install, which adds the marketplace first if needed, under the same policy checks as claude plugin marketplace add. And CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS sets the base backoff delay when an overloaded request comes back with a 529.

Mods get prompt caching and the autocomplete list

Three additions for mods. $.model.complete can cache now: prompt and system take blocks of text, and cache: true on a block caches the request up to it. prompt.autocomplete is a new event a mod hooks to add its own rows to the prompt box’s completion list. And agent.spawn now sees workflow agents too, with their run and index, so a mod can refuse them.

Next to that sits a long run of hook fixes, and they share a pattern: when the hooks worker restarted, calls used to go through without the plugins’ permission hooks. A tool.check hook answering allow could start a tool that actually needs your answer. A mod whose hook fails after calling next(e) is now reported as failed, by name, instead of as a refusal. All places where ordering mattered more than it looked.

Six permission fixes, one of them flagged as Security

Exactly one carries the Security label: PreToolUse approvals and auto mode were bypassing the permission prompt for file reads from UNC paths, meaning network shares.

The other five read like a continuation of the sweep in 2.1.290. Sandboxed commands could read the staged file copies of /ultrareview uploads under ~/.claude/seed-admin. A managed-settings read-deny path that appeared or re-pointed mid-session didn’t end credential injection or drop project grants beneath it. A notebook or PDF read on macOS and Windows could return a file outside what was approved, through a link swapped mid-read — the same race as two versions ago, with different file types. A tampered on-disk cache of server-managed settings could switch off the built-in policy plugin while the settings fetch was failing. And rm -rf on the 8.3 short name or another Windows spelling of the home folder wasn’t treated as removing it.

Schedules, loops, and a 256KB limit that said nothing

Three fixes cover things that failed quietly. Saved scheduled tasks created after /resume, /branch or /clear never fired. A /loop in a background session stopped when the process restarted, because its pending wakeup was lost. And claude -p dropped a scheduled wakeup entirely.

Plus: @-mentioned text files over 256KB used to be left out silently; now Claude is told the size and to read it in portions. Read returned only the first entry, with no error, when a PDF’s pages was a list such as “6,9,15”. NO_PROXY was ignored for Claude Code’s own API requests whenever HTTPS_PROXY was set. And an MCP tool with a name longer than 128 characters made every request fail; it’s now left out and named in an error.

The desktop app stops touching your dotfiles

Claude Desktop v2.26454.0 shipped the same day, with Claude Code 2.1.289 inside. The line that sticks: computer use on macOS no longer writes to hidden files and folders in your home directory, which includes ~/.vimrc and ~/.aws.

A second one is concrete enough to remember. A skill with a very long description could cause every skill stored on the machine to be removed. Past 1,024 characters it’s now refused with the reason given.

And one deadline falls today. inferenceGatewayAuthScheme: "sso" has no end date in this release and later: if inferenceCredentialKind isn’t set, they keep reading sso as interactive. Earlier releases stop accepting it on October 7, 2026.

Two releases, same pattern as last week

What’s new in 2.1.292 fits in five lines. The rest is cleanup, and the largest block of it is permissions again: a network path, a swapped link, a tampered settings cache, a Windows path name. Then hooks that ran in the wrong order.

The pleasant part is that the entries are halfway to an explanation rather than a formula. The less pleasant part is how often the same class of problem comes back. If you set deny rules and install mods, keep reading these for a few more weeks.

Sources

Claude CodeAnthropicReleasesModsSecurity