- Claude
- Claude Code 2.1.289
- Developer
Claude Code 2.1.289 tightens permission rules and plugin boundaries
This stable Claude Code update fixes permission handling for compound commands, symlink reads and shell environment prefixes. It also stops plugins from replacing organization MCP sign-in descriptions and adds agent spawning/state APIs. These changes matter to teams relying on approval and deny rules, but do not establish that every security risk is resolved.
Published Updated 1 source
Primary source
Anthropic · October 3, 2026
Read the original: Claude Code 2.1.289 tightens permission rules and plugin boundariesOpens Anthropic in a new tab. Read it there before you rely on the summary above.
Unlock the full brief free.
- What to check before you trust this story, written down
- Each verified source, with why it matters and who published it
- A note whenever a source has been withdrawn
- Thirty days of stories to browse, not seven
Related on Rise Productive
The newsletter
What I built and what changed in AI, about once a week.
