Product update

Claude Code 2.1.289 fixes permission checks and plugin stability

Event time 1 independent sourceEditorial score 73/100Updated here

The short version

Anthropic released Claude Code 2.1.289 with fixes to Bash deny and ask rules, IDE symlink Read restrictions, and managed MCP sign-in tool descriptions. The release also adds agent.spawn for teammates.

What changed

Permission and plugin fixes ship alongside teammate API additions.

What it means for you

Users of managed machines and plugin integrations can review the changed permission behavior.

The release notes describe fixes for deny or ask rules in compound shell commands and sandbox auto-allow paths. They also cover Read restrictions on IDE-selected or mentioned files reached through symlinks, and prevent user-installed plugins from rewriting managed MCP sign-in tool descriptions.

The notes add agent.spawn for teammates, one agent identifier across plugin hook events, and idle and waiting states in $.agent.list().

These are release-note claims, rather than an independent security audit. Validate your permission rules and plugin workflows after upgrading. The update also reverts a VS Code authentication-status change from 2.1.288 and lists several terminal and plugin rendering fixes.

Related catalog entry

Fact check

  • VerifiedThe release notes describe fixes for deny or ask rules in compound shell commands and sandbox auto-allow paths. They also cover Read restrictions on IDE-selected or mentioned files reached through symlinks, and prevent user-installed plugins from rewriting managed MCP sign-in tool descriptions.Evidence
  • VerifiedThe notes add agent.spawn for teammates, one agent identifier across plugin hook events, and idle and waiting states in $.agent.list().Evidence

Coverage timeline

  1. Primary sourceAnthropic
    Anthropic