Claude Code 2.1.289 fixes permission checks and plugin stability
The short version
Anthropic released Claude Code 2.1.289 with fixes to Bash deny and ask rules, IDE symlink Read restrictions, and managed MCP sign-in tool descriptions. The release also adds agent.spawn for teammates.
What changed
Permission and plugin fixes ship alongside teammate API additions.
What it means for you
Users of managed machines and plugin integrations can review the changed permission behavior.
The release notes describe fixes for deny or ask rules in compound shell commands and sandbox auto-allow paths. They also cover Read restrictions on IDE-selected or mentioned files reached through symlinks, and prevent user-installed plugins from rewriting managed MCP sign-in tool descriptions.
The notes add agent.spawn for teammates, one agent identifier across plugin hook events, and idle and waiting states in $.agent.list().
These are release-note claims, rather than an independent security audit. Validate your permission rules and plugin workflows after upgrading. The update also reverts a VS Code authentication-status change from 2.1.288 and lists several terminal and plugin rendering fixes.
Fact check
- VerifiedThe release notes describe fixes for deny or ask rules in compound shell commands and sandbox auto-allow paths. They also cover Read restrictions on IDE-selected or mentioned files reached through symlinks, and prevent user-installed plugins from rewriting managed MCP sign-in tool descriptions.Evidence
- VerifiedThe notes add agent.spawn for teammates, one agent identifier across plugin hook events, and idle and waiting states in $.agent.list().Evidence
Coverage timeline
- Primary sourceAnthropicAnthropic