Skip to main content

News

  • Claude
  • Claude Code 2.1.289
  • Developer

Claude Code 2.1.289 tightens permission rules and plugin boundaries

This stable Claude Code update fixes permission handling for compound commands, symlink reads and shell environment prefixes. It also stops plugins from replacing organization MCP sign-in descriptions and adds agent spawning/state APIs. These changes matter to teams relying on approval and deny rules, but do not establish that every security risk is resolved.

Published Updated 1 source

Primary source

Anthropic · October 3, 2026

Read the original: Claude Code 2.1.289 tightens permission rules and plugin boundaries

Opens Anthropic in a new tab. Read it there before you rely on the summary above.

Unlock the full brief free.

  • What to check before you trust this story, written down
  • Each verified source, with why it matters and who published it
  • A note whenever a source has been withdrawn
  • Thirty days of stories to browse, not seven

This is not an account: there is no password, and the unlock is a cookie in this browser. You also join the Rise Productive newsletter from Demetri Panici, about once a week: what I built and what changed in AI. We'll email you a link to confirm, and you can unsubscribe in one click. The same signup unlocks every free tool on the site. How your email is handled.

Claude Code 2.1.289 tightens permission rules and plugin boundaries | Rise Productive