Claude Code v2.1.292:修复网络路径越权与安全漏洞,新增插件市场与子代理参数
v2.1.292
推荐理由
涉及可被外部触发的安全漏洞修复(PreToolUse 绕过),建议开发者立即升级至 v2.1.292 以消除权限绕过风险。
What's changed
变更内容
- Added --marketplace <source> to claude plugin install: adds the marketplace if needed, under the same policy checks as claude plugin marketplace add, then installs the plugin from it
- Added an effort parameter to the Agent tool, so Claude runs a sub-agent at the effort level you ask for
- Added CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS environment variable to set a longer base delay for the backoff when retrying an overloaded (529) request
- Added prompt.autocomplete, an event a mod hooks to add its own rows to the prompt box's autocomplete list
- Added prompt caching to $.model.complete for mods: prompt and system take blocks of text, and cache: true on a block caches the request up to it
- Added workflow agents to the agent.spawn mod hook, with their run and index, so a mod can refuse them
- Fixed subagent definitions with permissionMode: auto entering auto mode when auto mode is unavailable (disabled by settings, circuit breaker, or a model that doesn't support it)
- Fixed sandboxed commands being able to read the staged file copies of /ultrareview uploads under ~/.claude/seed-admin
- Fixed a managed sandbox read-deny path (and user ones beside it) that appears or re-points mid-session not dropping project grants inside it or ending credential injection from files it covers
- Fixed a notebook or PDF read on macOS and Windows being able to return a file outside what was approved, through a link swapped in mid-read
- Fixed a tampered on-disk cache of server-managed settings being able to switch off or unseat the built-in policy plugin while the settings fetch failed
- Fixed rm -rf on the 8.3 short name or another alternate Windows spelling of the home folder or a drive not being treated as removing it
- Security: Fixed PreToolUse hook approvals and auto mode bypassing the permission prompt for file reads from network (UNC) paths
- Fixed a skill's or slash command's allowed-tools rule coming back in a later turn when you leave auto mode or plan mode partway through that turn
- Fixed NO_PROXY being ignored for Claude Code's own API requests (sign-in, policy, feedback, artifacts) when HTTPS_PROXY is set
- Fixed an MCP tool with a name longer than 128 characters making every request fail; that tool is now left out and an MCP error names it
- Fixed claude plugin commands such as marketplace add and install running before an organization's managed settings had loaded on a first run
- Fixed one-shot claude -p and Agent SDK runs stopping a background command 5 seconds after the final result, and one-shot claude -p runs dropping a scheduled wakeup; both are now waited for
- Fixed plan mode not being restored when resuming a session from the claude --resume session picker or with /resume
- Fixed saved scheduled tasks created after /resume, /branch or /clear never firing, and saved tasks ignoring later creates and deletes after two writes to the tasks file milliseconds apart
- Fixed a background session's /loop silently stopping when the session's process restarted (for example after a crash), because its pending wakeup was lost
- Fixed Grep and Glob reporting no matches when the file or folder they were given could not be read; Claude now retries once or tells you
- Fixed the Read tool returning only the first entry, with no error, when a PDF's pages was a list such as "6,9,15"; it now returns an error saying to read each page or range separately
- Fixed @-mentioned text files over 256KB being left out silently: Claude is now told the file's size and to read it in portions
- Fixed the usage limit alert repeating once per background agent when agents failed on a limit that had already stopped the main conversation
- Fixed Remote Control viewers seeing an empty subagent pane for background subagents in sessions hosted by the desktop app or an IDE
- Fixed cross-session delivery notices showing two sessions with similar names as one recipient, and the expiry notice blaming the desktop app when a terminal session let the message lapse
- Fixed Send now in the desktop app ending the subagent a turn was waiting on when another message was already queued
- Fixed /bug, /share and /feedback <text> starting over after Ctrl+O or Ctrl+Z while a report was being sent, and closing as cancelled after it had been sent
- Fixed /remote-env replacing your saved default environment when you pressed Enter right away: the list now opens on your default, and no row has a check mark when no default is in effect
- Fixed some pasted text reaching Claude as typed text when several pastes overlapped in one prompt
- Fixed vim mode leaving the cursor past the end of a line, j/k losing their column on shorter lines, and f/t/F/T/;/, jumping to, or deleting up to, a match on another line of the prompt
- Fixed /add-dir path box letting Shift+Enter or a paste add a line break, and treating fast-typed "tab", "up" or "down" as those keys
- Fixed fast typing, input-method text and decomposed accents being dropped while a prompt footer row was selected, and ! leaving the row selected
- Fixed fullscreen mode sending a full-screen clear on every window resize and Ctrl+L when iTerm2 is detected, which may be what filled iTerm2's scrollback with stale pages
- Fixed a spurious "could not be examined" note for @-words that name no file when a Read deny rule is set and the working directory is under a symlink
- Fixed "instruction file not loaded" lines going stale or missing after /cd or a permission change, and added a transcript line when a nested one isn't loaded
- Fixed a compaction summary that repeated /name letting Claude invoke a skill that is reserved for the user
- Fixed Write, Edit, NotebookEdit and LSP rows, and single Read, Grep and Glob rows, hiding why a mod denied the call: the row now shows the reason
- Fixed a cloud session showing a turn that never ended when its worker was stopped just as the turn finished
- Fixed cloud sessions with a large transcript sometimes asking for a permission again after it was approved
- Fixed scheduled tasks and other queued notifications being lost in cloud sessions when a message was retried or edited while Claude was reading them
- Fixed cloud sessions forgetting the thinking setting chosen in the client when the session's container restarted
- Fixed Cowork cloud sessions saying a proxy blocked artifacts when Anthropic couldn't confirm the organization's settings
- Fixed plugins whose hooks module makes many $.state calls through one const taking minutes to load or validate
- Fixed claude plugin validate listing a matcher or state value for a hooks module that the engine reads from elsewhere
- Fixed claude plugin validate listing a $.state value read through a top-level var that was declared again or reassigned; such a module is now refused
- Fixed a plugin's served $ method restarting the hook origin, which could run a guard hook with a .catch above it again without end
- Fixed plugin interface calls made while the plugin hooks worker restarts running without the hooks other plugins put on them
- Fixed a mod's config.set, state.set, env.set or agent.spawn hook that denies after calling next(e) being answered as a refusal: the hook is now reported as failed, by name
- Fixed /theme, the /config Theme menu and the first-run theme step saving a theme before a plugin's config.set hook was asked
- Fixed a plugin's tool.check hook answering allow running a tool that requires your answer (a question, a plan approval) without showing its dialog
- Fixed a mod's start-up prompt, command or subagent being queued a second time when the hooks worker was replaced
- Fixed a mod's hook that called next(e) and then failed while the turn was interrupted letting the call through; the call is now rejected
- Fixed a plugin's prompt drop or setting deny being ignored when its reason was longer than 4,096 characters
- 为 claude plugin install 添加了 --marketplace <source> 参数:在需要时添加市场插件,遵循与 claude plugin marketplace add 相同的策略检查,然后从中安装插件
- 为 Agent 工具添加了 effort 参数,使 Claude 以你指定的努力级别运行子代理
- 添加了 CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS 环境变量,用于设置重试过载(529)请求时的退避基础延迟时间
- 添加了 prompt.autocomplete 事件,供 mod 挂钩使用,以便向提示框的自动补全列表中添加自定义行
- 为 $.model.complete 中的 mod 添加了提示缓存功能:提示和系统提示采用文本块,对文本块设置 cache: true 可缓存直至该块的请求
- 在 agent.spawn mod 钩子中添加了工作流代理及其运行状态和索引,以便 mod 可以拒绝它们
- 修复了 permissionMode: auto 的子代理定义在自动模式不可用时(被设置禁用、熔断器触发或模型不支持)仍进入自动模式的问题
- 修复了沙盒命令能够读取 ~/.claude/seed-admin 下 /ultrareview 上传的分阶段文件副本的问题
- 修复了托管沙盒的读取拒绝路径(及其旁边的用户路径)在会话中途出现或重新指向时,未撤销其中的项目权限或未终止对其覆盖文件的凭据注入的问题
- 修复了在 macOS 和 Windows 上读取笔记本或 PDF 时,通过读取中途替换链接,可能返回未经批准的文件外路径的问题
- 修复了篡改服务器管理设置的磁盘缓存,在设置获取失败期间关闭或移除内置策略插件的问题
- 修复了对主文件夹或驱动器的 8.3 短名称或其他备用 Windows 拼写执行 rm -rf 时,未被正确识别为删除操作的问题
- 安全修复:修复了 PreToolUse 钩子审批和自动模式绕过从网络(UNC)路径读取文件的权限提示的问题
- 修复了在离开自动模式或计划模式时,技能或斜杠命令的 allowed-tools 规则在当前轮次中途退出后仍返回的问题
- 修复了在设置 HTTPS_PROXY 时,Claude Code 自身 API 请求(登录、策略、反馈、制品)忽略 NO_PROXY 的问题
- 修复了名称超过 128 个字符的 MCP 工具导致所有请求失败的问题;现在该工具将被排除,并在 MCP 错误中指明其名称
- 修复了首次运行时,claude plugin 命令(如 marketplace add 和 install)在组织托管设置加载完成前即执行的问题
- 修复了单次运行 claude -p 和 Agent SDK 在最终结果输出后 5 秒停止后台命令,以及单次运行 claude -p 丢弃计划唤醒的问题;现在会等待这些操作完成。
- 修复了从 claude --resume 会话选择器或通过 /resume 恢复会话时,计划模式未恢复的问题。
- 修复了通过 /resume、/branch 或 /clear 创建的已保存计划任务从未触发,以及已保存的任务在两次写入 tasks 文件(间隔毫秒级)后会忽略后续的创建和删除操作的问题。
- 修复了当会话进程重启(例如崩溃后)时,后台会话的 /loop 因丢失待处理的唤醒而静默停止的问题。
- 修复了 Grep 和 Glob 在无法读取指定的文件或文件夹时报告无匹配项的问题;Claude 现在会重试一次或告知用户。
- 修复了 Read 工具在 PDF 页面为 "6,9,15" 这样的列表时,仅返回第一项且无错误提示的问题;现在会返回错误提示,要求分别读取每个页面或范围。
- 修复了 @提及的大小超过 256KB 的文本文件被静默忽略的问题:现在 Claude 会获知文件大小并分段读取。
- 修复了当代理因已达到限制而失败(该限制已停止主对话)时,使用量限制警报在每个后台代理中重复出现一次的问题。
- 修复了远程控制面板查看者在由桌面应用或 IDE 托管的会话中,看到后台子代理的子代理窗格为空的问题。
- 修复了跨会话投递通知将名称相似的两个会话显示为一个收件人,以及在终端会话导致消息过期时将责任归咎于桌面应用的过期通知问题。
- 修复了桌面应用中点击“立即发送”会在另一条消息已在队列中时,提前结束正在等待下一轮响应的子代理的问题。
- 修复了在发送报告过程中按 Ctrl+O 或 Ctrl+Z 会导致 /bug、/share 和 /feedback <text> 重新开始,以及在报告已发送后将其关闭为已取消的问题。
- 修复了 /remote-env 在您立即按下 Enter 时替换已保存的默认环境的问题:现在列表会在默认环境上打开,且当没有生效的默认环境时,没有任何行带有勾选标记。
- 修复了当单个提示词中多次粘贴重叠时,部分粘贴文本以输入文本形式传递给 Claude 的问题。
- 修复了 vim 模式下光标停留在行尾之后、j/k 在较短的行上丢失列位置,以及 f/t/F/T/;/, 跳转到或向上删除至提示词其他行的匹配项的问题。
- 修复了 /add-dir 路径框允许 Shift+Enter 或粘贴添加换行符,并将快速输入的 "tab"、"up" 或 "down" 误识别为相应按键的问题。
- 修复了快速输入时,选中提示底部行会导致输入法文本和分解的重音符号丢失,以及 ! 键使该行保持选中的问题
- 修复了全屏模式下,检测到 iTerm2 时每次窗口调整大小或按下 Ctrl+L 都会发送全屏清除指令的问题,这可能是导致 iTerm2 滚动缓冲区充满过期页面的原因
- 修复了在设置 Read 拒绝规则且工作目录位于符号链接下时,对于未命名任何文件的 @-words(以 @ 开头的词),出现虚假的“无法检查”提示的问题
- 修复了执行 /cd 命令或权限变更后,“指令文件未加载”的行变得过时或缺失的问题,并在嵌套指令未加载时添加了转录行
- 修复了压缩摘要中重复显示 /name 的问题,该问题允许 Claude 调用专属于用户的技能
- 修复了 Write、Edit、NotebookEdit 和 LSP 行,以及单个 Read、Grep 和 Glob 行隐藏模块拒绝调用原因的问题:现在这些行会显示具体原因
- 修复了云会话在轮次刚结束时其工作进程被停止,从而显示一个从未结束的轮次的问题
- 修复了拥有大型转录记录的云会话在权限已批准的情况下,有时再次请求权限的问题
- 修复了在 Claude 读取消息时重试或编辑消息,导致云会话中计划任务和其他排队通知丢失的问题
- 修复了云会话在会话容器重启后忘记客户端中选择的思考模式设置的问题
- 修复了当 Anthropic 无法确认组织设置时,Cowork 云会话错误地声称代理阻止了工件生成的问题
- 修复了插件问题,其中某些插件的 hooks 模块通过一个 const 变量发起大量 $.state 调用,导致加载或验证耗时数分钟
- 修复了 claude 插件 validate 命令列出 hooks 模块的匹配器或状态值的问题,而这些值实际上是由引擎从其他地方读取的
- 修复了 claude 插件 validate 命令列出通过顶层变量读取的 $.state 值的问题,如果该变量被重新声明或重新赋值,此类模块现将被拒绝
- 修复了插件提供的 $ 方法重启钩子源的问题,这可能导致带有 .catch 的上游守卫钩子无限循环运行
- 修复了在插件钩子工作进程重启期间进行的插件接口调用,此时其他插件设置的钩子尚未生效的问题
- 修复了 mod 的 config.set、state.set、env.set 或 agent.spawn 钩子在调用 next(e) 后拒绝响应时,被错误地回答为拒绝的问题:现在该钩子会以名称报告为失败
- 修复了 /theme 命令、/config 主题菜单以及首次运行时的主题步骤,在未询问插件的 config.set 钩子的情况下就保存主题的问题
- 修复了插件的 tool.check 钩子允许在无需用户回答(如问题、计划审批)的情况下运行工具,且未显示其对话框的问题
- 修复了当 hooks worker 被替换时,模块的启动提示、命令或子代理被重复排队两次的问题
- 修复了模块的钩子在调用 next(e) 后失败,且在回合中断时仍让该调用通过的问题;现在该调用会被拒绝
- 修复了当插件的拒绝原因长度超过 4,096 个字符时,其提示词丢弃或设置拒绝被忽略的问题
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力