v2.1.222
Claude CodeSummary
This release focuses on enhancing security and usability within agent sessions. Key improvements include better isolation for destructive Git commands, more robust handling of tool restrictions, and clearer error reporting for usage credits and connection issues. Additionally, diff views have been refined to use raw git blob content for greater accuracy.
New Features
- Improved auto mode safety by evaluating messages sent to other agent sessions via SendMessage with the permission classifier before dispatch.
- Improved refusal when Claude tries to invoke a skill with disable-model-invocation, now instructing Claude to ask you to run the skill instead of replicating its workflow.
- Improved the /diff view, Remote Control workspace diff, and file-edit diffs in Claude Code on the web sessions to use raw git blob content, ignoring workspace-configured diff drivers and textconv.
Bug Fixes
- Fixed worktree-isolated sessions and their subagents being able to run destructive git commands against the main checkout; isolation now applies to file edits and Bash in every session type.
- Fixed PreToolUse auto-allow hooks bypassing tool restrictions in background agent tasks (summaries, compaction, renames).
- Fixed /usage-credits on Team and Enterprise showing "you've already sent a usage credit request" for members whose earlier request was dismissed, blocking them from sending a new one.
- Fixed the startup connectivity check hanging and then failing behind an HTTPS proxy; it now uses the same proxy-aware transport as API requests and times out with a clear message.
- Fixed "Connection closed mid-response" errors being reported on responses that had actually completed.
- Fixed /usage overattributing usage to MCP servers: a server's share now reflects only the requests that actually consumed its tool results, instead of every turn after any call to it.
- Fixed sessions not linking to pull requests created after the branch was pushed, including through the GitHub REST API.
- Fixed org-restricted model: opus-style subagent and teammate family aliases dropping to the parent model instead of stepping down to the newest org-allowed model in the family.
- Fixed stream idle timeout firing on custom ANTHROPIC_BASE_URL gateways despite server keep-alive pings arriving on the wire.
- Fixed claude.ai connectors being falsely marked as needing authorization when the session token is invalid — they now show a /login hint instead.
- Fixed tool errors not being displayed for tools no longer available locally, for example after an MCP server is removed.
- Fixed SendMessage rejecting a long summary — it now truncates instead, so sends no longer fail on a character limit.
- Fixed the spinner's effort label in a subagent's transcript view showing the session's effort level instead of the subagent's own effort: setting.
- Fixed rare crashes when a file watcher hit a filesystem error or during file-watcher teardown.
- Fixed screen readers re-reading the whole input line on every backspace in --ax-screen-reader mode — end-of-line deletions now echo just the deleted characters.
- Fixed host model-selection keys not taking precedence over a stale on-disk managed-settings.json when CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST is set.
Improvements
- Changed Remote Control auto-start so repo-local settings (.claude/settings.json or .claude/settings.local.json) can no longer turn it on (they can still turn it off); enable it at user scope via /config.