跳到主内容
@wquguru
精选88Claude Code(GitHub Releases)AI 编程与模型

Claude Code v2.1.287:新增内置插件、MCP URL提示与多项安全及稳定性修复

v2.1.287

原文
发到 X
推荐理由

本次更新包含破坏性安全修复(rm 命令保护失效),开发者必须升级以避免误删文件风险;同时引入了 Mods 插件架构和 MCP URL 提示等新范式,建议立即升级并审查配置。

What's changed

变更内容

  • Added Claude Mods: plugins may now modify deeper behavior
  • Added You should know, a built-in mod where a side agent watches your back and flags things you or Claude might miss. Turn it on with /plugin enable cc-plugin-you-should-know@builtin (for first-party sessions with telemetry on)
  • Added an n:<text> filter to the agents view that matches session names and tasks; a filter now shows matches in collapsed sections and Enter opens the first match
  • Added prompt_text to the OpenTelemetry user_prompt event, a copy of prompt for backends that nest dotted keys; drop or mask it wherever you drop or mask prompt (#70763)
  • Added URL prompts from MCP servers on the 2025-11-25 protocol, for example to sign in. If a server no longer connects after this update, add "bareElicitationCapability": true to its MCP config entry
  • Windows: Added a startup warning when denying the Bash tool also turns off the PowerShell tool, so Claude has no shell tool
  • Self-hosted runner: Added a built-in gh api (REST only) for sessions that use Anthropic-managed git on macOS and Linux machines where the GitHub CLI is not installed
  • Fixed fast mode staying off in remote sessions owned by an agent with no user account, even when the organization allows it
  • Fixed Remote Control not receiving messages for minutes at a time when a reconnect request got no response; it now gives up after 30 seconds and retries
  • Fixed hooks configured with asyncRewake waking Claude over and over with "found issues" notifications when the hook's script file is missing; the broken hook is now reported once
  • Fixed tool heartbeats not reaching SDK hosts while the model's response stream was stalled with no data arriving
  • Fixed Bedrock and Vertex startup model checks ignoring an enforced availableModels list, which could collapse /model to one Opus row
  • Fixed the Claude in Chrome browser picker showing a JSON parse error when Chrome could not be reached
  • Fixed picking Fable in /model on a claude.ai login saving the current version's id, so your saved default now follows the newest Fable like Opus and Sonnet do
  • Fixed switching between Opus 5.5 and Sonnet 5.5 (/model, opusplan) rewriting earlier MCP tool announcements, which could drop earlier extended thinking
  • Fixed Amazon Bedrock Guardrails blocks that arrive mid-response ending the turn with an API error instead of the guardrail's message when the reply began with thinking
  • Fixed a dangerous rm (such as one on / or the home directory) losing its always-ask safeguard when the same command also redirected output to a ~ or wildcard path
  • Fixed claude -p and SDK sessions repeating a model fallback on every later message after the model was switched while a reply was running
  • Fixed a folder's CLAUDE.md being attached a second time after resuming a session or after a compaction
  • Fixed background sessions that could not be reopened from claude agents after the agent exited and removed the worktree the session was started in
  • Fixed /advisor pairing checks: Sonnet 5.5 can now advise Opus 4.7 and 4.8, and advisors the API would refuse are flagged up front instead of being silently dropped
  • Fixed Bash permission prompts showing internal parser names such as "Contains simple_expansion" instead of a plain explanation
  • Fixed a cause of fullscreen sessions on slow or busy machines exiting with "Claude Code exited after an unrecoverable interface error" while a scroll key was held in a long conversation
  • Fixed organization per-tool permission ceilings being silently dropped for an MCP tool named __proto__
  • Fixed Claude being told to page large MCP results saved as JSON with Read's offset and limit, which cannot split one long line
  • Fixed the commit attribution reminder being delivered inside a tool result after a compaction
  • Fixed screen reader mode leaving the cursor away from the typed text in search boxes (such as /resume and /permissions) and sign-in code fields
  • Fixed screen reader mode refusing Enter with nothing typed on /rewind's summarize options, whose added context is optional
  • Fixed screen reader mode showing a "Tab to amend" hint on approval prompts, where Tab does nothing
  • Fixed screen reader mode listing arrow keys that do nothing in /permissions and /mcp, and saying "Select with numbers" in empty menus or while a search box has the keys
  • Fixed screen reader mode leaving out the changed lines in file edit approval prompts and other diffs
  • Fixed screen reader mode sending the claude --teleport progress screen, and an MCP form field while it is being checked, to the screen reader again on every spinner frame
  • Fixed CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS not removing the structured-output format from session-title and prompt-hook requests, which Bedrock-backed gateways reject
  • Fixed screen reader mode leaving out the top lines of a second approval prompt, a changed /config row or the rejected-plan line when the previous screen was taller than the terminal window
  • Fixed --include-partial-messages sending a cut-short reply's message_stop late or never, so apps could show the reply as still in progress
  • Fixed claude agents sometimes not showing the permission prompt a background session is waiting on
  • Fixed /ultrareview giving advice about .git/info/attributes when the upload stops on a committed .gitattributes it cannot read, such as one saved as UTF-16
  • Fixed claude remote-control failing to register behind an HTTP proxy with a misleading "Check your organization permissions" error (#97352)
  • Fixed sandboxed Bash commands on Linux inheriting an open handle on the Claude Code executable
  • Fixed the running-tool dot and three spinners still moving with the "Reduce motion" setting on, and /rewind's confirm screen updating its "ago" time while you type a note
  • Fixed times in claude agents changing every second in screen reader mode; they now change at most every 10 seconds
  • Fixed a revoked claude.ai login showing a generic API Error: 401 instead of "OAuth token revoked"; in -p mode the error now starts with "Failed to authenticate"
  • Fixed /ultrareview upload refusals advising you to copy a variable named by a repository's settings file into your own user settings
  • Fixed --output-format stream-json and the SDK not streaming the turns of a context: fork skill run by typing /<skill> as the prompt, as they do for the Skill tool's fork
  • Fixed /feedback and /bug: the pre-filled GitHub issue no longer includes your recent error messages, and the confirmation screen now lists them as part of the report
  • Fixed claude plugin marketplace add --sparse and git-subdir plugin installs failing with "transport 'http' not allowed" when the repository is served over plain http
  • Fixed cloud sessions sometimes losing the earlier conversation when the session restarted while it was being compacted
  • Fixed a plugin reload that overlapped the startup --plugin-url download corrupting the session's cached copy of the plugin archive
  • Fixed /desktop quoting partial output when opening Claude Desktop timed out or printed too much output; the error now names the cause
  • Fixed an MCP connector tool call occasionally running twice, or the connector's calls failing until restart, when its server changed which MCP protocol version it supports
  • Fixed SessionStart hooks from synced plugins not running in new cloud sessions
  • Fixed the transcript's "N hooks ran" summary and the verbose debug log's matched-hooks count including Claude Code's internal callbacks, so one configured hook no longer shows as two
  • Fixed files Claude sends from cloud and Remote Control sessions failing when the upload finished just after the 30-second timeout; it now waits 35 seconds
  • Fixed repositories added mid-session in cloud and SDK sessions not loading their skills and plugins, and loading CLAUDE.md late, after Claude changed directory
  • 新增 Claude Mods:插件现在可以修改更深层的行为
  • 新增 You Should Know,这是一个内置 mod,其中有一个辅助代理在后台监视并标记你或 Claude 可能遗漏的内容。通过 /plugin enable cc-plugin-you-should-know@builtin 开启(适用于 telemetry 开启的第一方会话)
  • 在 agents 视图中新增了 n:<text> 过滤器,用于匹配会话名称和任务;过滤器现在会在折叠部分中显示匹配项,按 Enter 键可打开第一个匹配项
  • 在 OpenTelemetry user_prompt 事件中新增 prompt_text,作为嵌套点号键的后端使用的提示词副本;在你丢弃或屏蔽 prompt 的任何地方也丢弃或屏蔽它(#70763)
  • 在 2025-11-25 协议下,MCP 服务器支持 URL 形式的提示词,例如用于登录。如果更新后服务器不再连接,请在其 MCP 配置条目中添加 "bareElicitationCapability": true
  • Windows:当拒绝 Bash 工具的同时也会关闭 PowerShell 工具,导致 Claude 没有任何 shell 工具时,新增启动警告
  • 自托管运行器:为使用 Anthropic 托管 git 的 macOS 和 Linux 机器上的会话新增内置 gh api(仅限 REST),前提是未安装 GitHub CLI
  • 修复了即使组织允许,由没有用户账户的代理拥有的远程会话中快速模式仍保持关闭的问题
  • 修复了重连请求无响应时 Remote Control 长时间(数分钟)收不到消息的问题;现在它在 30 秒后放弃并重试
  • 修复了当 hook 的脚本文件缺失时,配置为 asyncRewake 的 hook 会反复唤醒 Claude 并发送“发现问题”通知的问题;现在损坏的 hook 仅报告一次
  • 修复了在模型响应流停滞且无数据到达期间,工具心跳无法到达 SDK 主机的问题
  • 修复了 Bedrock 和 Vertex 启动时的模型检查忽略强制可用的 availableModels 列表的问题,这可能导致 /model 命令仅显示一行 Opus
  • 修复了 Chrome 浏览器中的 Claude 选择器在无法访问 Chrome 时显示 JSON 解析错误的问题
  • 修复了在 claude.ai 登录状态下通过 /model 选择 Fable 时会保存当前版本 id 的问题,因此你保存的默认值现在会像 Opus 和 Sonnet 一样跟随最新的 Fable 版本
  • 修复了在 Opus 5.5 和 Sonnet 5.5 之间切换(/model、opusplan)时会重写早期 MCP 工具公告的问题,这可能导致丢失早期的扩展思考内容
  • 修复了 Amazon Bedrock Guardrails 在响应中途拦截时,若回复以思考开头,会以 API 错误结束轮次而非显示 guardrail 消息的问题
  • 修复了危险 rm(例如针对 / 或主目录的 rm)在相同命令也将输出重定向到 ~ 或通配符路径时,丢失其始终询问保护机制的问题
  • 修复了 claude -p 和 SDK 会话在模型切换且回复正在运行时,对后续每条消息重复执行模型回退的问题
  • 修复了恢复会话或进行压缩后,文件夹的 CLAUDE.md 被附加两次的问题
  • 修复了后台会话在代理退出并移除会话启动所在的 worktree 后,无法从 claude agents 重新打开的问题
  • 修复了 /advisor 配对检查:Sonnet 5.5 现在可以建议 Opus 4.7 和 4.8,并且 API 会拒绝的建议者会在前端被标记出来,而不是被静默丢弃
  • 修复了 Bash 权限提示显示内部解析器名称(如 "Contains simple_expansion")而非普通解释的问题
  • 修复了在缓慢或繁忙的机器上,全屏会话在长对话中按住滚动键时,以 "Claude Code exited after an unrecoverable interface error" 退出的问题
  • 修复了名为 __proto__ 的 MCP 工具的组织级单工具权限上限被静默丢弃的问题
  • 修复了 Claude 被告知使用 Read 的 offset 和 limit 分页保存为 JSON 的大型 MCP 结果,而该操作无法分割一行长文本的问题
  • 修复了压缩后提交归属提醒出现在工具结果内部的问题
  • 修复了屏幕阅读器模式下,光标未停留在搜索框(如 /resume 和 /permissions)和登录代码字段中输入的文本旁的问题
  • 修复了屏幕阅读器模式下,在 /rewind 的摘要选项未输入任何内容时拒绝回车键的问题,因为这些选项的附加上下文是可选的
  • 修复了屏幕阅读器模式下,在批准提示中显示 "Tab to amend" 提示,但 Tab 键实际上无效的问题
  • 修复了屏幕阅读器模式下,列出在 /permissions 和 /mcp 中无效的箭头键,并在空菜单或搜索框拥有焦点时说 "Select with numbers" 的问题
  • 修复了屏幕阅读器模式下,文件编辑批准提示和其他差异中遗漏已更改行的问题
  • 修复了屏幕阅读器模式下,每次旋转帧都将 claude --teleport 进度屏幕以及正在检查的 MCP 表单字段再次发送给屏幕阅读器的问題
  • 修复了 CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS 未从 session-title 和 prompt-hook 请求中移除结构化输出格式的问题,而基于 Bedrock 的网关会拒绝该格式
  • 修复了屏幕阅读器模式下,当上一屏比终端窗口高时,第二个批准提示的顶部行、已更改的 /config 行或被拒绝的计划行被遗漏的问题
  • 修复了 --include-partial-messages 在发送截断回复时,message_stop 延迟或从未触发,导致应用可能显示回复仍在进行中的问题
  • 修复了 claude agents 有时不显示后台会话正在等待的权限提示的问题
  • 修复了 /ultrareview 在上传因无法读取已提交的 .gitattributes(例如保存为 UTF-16 格式)而停止时,给出关于 .git/info/attributes 的建议的问题
  • 修复了 claude remote-control 在 HTTP 代理后注册失败并显示误导性“检查您的组织权限”错误 (#97352) 的问题
  • 修复了 Linux 上沙盒化 Bash 命令继承 Claude Code 可执行文件打开句柄的问题
  • 修复了在开启“减少动态效果”设置时,运行工具的点号和三个旋转图标仍持续移动,以及 /rewind 确认屏幕在您输入备注时更新其“多久以前”时间的问题
  • 修复了 claude agents 中时间在屏幕阅读器模式下每秒变化的问题;现在最多每 10 秒变化一次
  • 修复了撤销的 claude.ai 登录显示通用 API Error: 401 而非“OAuth token revoked”的问题;在 -p 模式下,错误信息现在以“Failed to authenticate”开头
  • 修复了 /ultrareview 上传拒绝建议将仓库配置文件命名的变量复制到用户自身配置中的问题
  • 修复了 --output-format stream-json 和 SDK 未流式传输通过键入 /<skill> 作为提示符运行的 context: fork 技能回合数据的问题,这与 Skill 工具的 fork 行为不一致
  • 修复了 /feedback 和 /bug:预填充的 GitHub Issue 不再包含您最近的错误消息,且确认屏幕现在将其列为报告的一部分
  • 修复了当仓库通过纯 http 提供服务时,claude plugin marketplace add --sparse 和 git-subdir 插件安装因“transport 'http' not allowed”而失败的问题
  • 修复了云会话在压缩过程中重启时有时会丢失早期对话的问题
  • 修复了插件重载与启动时的 --plugin-url 下载重叠,从而损坏会话缓存的插件归档副本的问题
  • 修复了 /desktop 在打开 Claude Desktop 超时或输出过多内容时引用部分输出的问题;现在错误信息会指明原因
  • 修复了当其服务器更改支持的 MCP 协议版本时,MCP 连接器工具调用偶尔运行两次,或连接器的调用在重启前失败的问题
  • 修复了同步插件的 SessionStart 钩子未在新云会话中运行的问题
  • 修复了转录的“N hooks ran”摘要以及详细调试日志中匹配钩子的计数,后者包含了 Claude Code 的内部回调,导致一个配置的钩子不再显示为两个
  • 修复了当上传在 30 秒超时后刚刚结束时,Claude 从云端和远程控制会话发送的文件失败的问题;现在它等待 35 秒
  • 修复了在云端和 SDK 会话中途添加的仓库无法加载其技能和插件,以及在 Claude 更改目录后才延迟加载 CLAUDE.md 的问题

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

关联信息,但可能不是同一事件