Blog
Articles, experience reports and news about Claude Code.
Claude Code 2.1.280: Opus 5.5 as the default everywhere, a symlink permission gap closed
2.1.280 makes Opus 5.5 the default model on every plan, including Pro and Team Standard, and fixes a symlinked write that could slip past acceptEdits, allow rules, and auto mode.
Claude Code 2.1.277-278: AGENTS.md, sandbox gap closed, server-side auto mode
2.1.277 reads AGENTS.md by default, hardens prompt-injection defenses on three fronts, and closes a Bash sandbox bypass. 2.1.278 bills auto mode server-side, except behind some gateways.
Claude Code 2.1.275-276: a broken gateway, fixed a day later, and npm locked down
2.1.275 broke every request behind some gateways, fixed by 2.1.276 the next day. Also: credentials leaking in plugin logs, npm install scripts now blocked, and a permission rule that never actually applied.
Claude Code 2.1.274: four permission blind spots closed in one release
2.1.274 fixes two new Bash permission-checker blind spots, an Edit approval preview that could point to the wrong location, and a secret leak in MCP connection errors.
Claude Code 2.1.273: auto-compact gets recalibrated, another Bash permission gap closed
2.1.273 fixes a bug that triggered auto-compact twice too early, closes a Bash permission gap in bypass mode, and adds forking a Remote Control session into a background one on your machine.
Claude Code 2.1.271-272: auto mode tightens its security checks
2.1.271 moves a skill's inline shell commands to default-mode permission rules, adds a dedicated review for subagent hand-back, per-command network access, and closes four Bash permission gaps. 2.1.272 ships only reliability fixes.
Claude Code 2.1.270: read-only git commands stop asking for permission again
2.1.270 fixes a 2.1.269 regression that made read-only git commands ask for permission again after a session had been running for a while.
Claude Code 2.1.269: a scoped permission rule, and your CLAUDE.md wins on attribution
2.1.269 closes a deny rule that leaked beyond its own settings file, restores your CLAUDE.md's priority over commit attribution, renames synced skills, and adds claude plugin eval.
Claude Code 2.1.268: leaked secrets, patched permissions, fixed third-party endpoints
2.1.268 fixes secrets exposed in error messages, several permission checks that let through exactly what they were meant to block, and the bug that broke Claude Code on third-party endpoints since 2.1.265.
Claude Code 2.1.267: two security gaps closed, prompt cache stabilized
A marketplace path check and three hook/plugin allowlists handled their own error cases wrong, fixed in 2.1.267, alongside about a dozen fixes that keep the prompt cache intact across session resumes.
Claude Code 2.1.265-266: a plugin security bypass closed, Windows sandbox fixed
A disguised symlink path was slipping past the plugin security check, the Windows sandbox rejected every file, and an LLM gateway broke authentication for a day.
Claude Code 2.1.263: a maintenance release with no published detail
Version 2.1.263 shipped September 6, 2026 with a single changelog line, bug fixes and reliability improvements, no individual fixes listed.
Claude Code 2.1.261: keybindings change, auto mode gets wary of links
Prompt word-editing keys now match Bash and keybindingFlavor stops doing anything, auto mode treats diagram-renderer links as uploads, and two more rm -rf disguises get caught.
Claude Code 2.1.260: Permission Rules Get Stricter, /diff Shows Up
Permission rules with parentheses left protected folders writable, a zsh trick slipped past Bash approval, and a new /diff panel shows your uncommitted changes live.
Claude Code 2.1.259: managed MCP and tighter permissions
A new managed setting pushes MCP servers to a whole organization, a gap in Bash deny rules closes, and allowedMcpServers changes scope on upgrade with no warning at all.
Claude Code 2.1.257-258: Fable 5.1, and a warier auto mode
Fable 5.1 becomes the default Fable model, with four times cheaper cache reads. Auto mode also tightens up: cloud credentials, reads outside the working directory, project-level bypassPermissions, and two isolation leaks closed.
Claude Code 2.1.252: three silent failures, and the hardening bill
Four fixes, no new features. A Bash output swap refusal that traces straight back to 2.1.251's hardening, an "always allow" that never saved the first time, a Remote Control session frozen by a sick connection rather than a dead one, and a failure notification big enough to blow past the API's 32MB request limit.
Claude Code 2.1.251: when the permission check ran too late
The month's biggest release fixes a whole family of bypasses: a symlink swapped after the green light, deny rules Grep walked straight past, a shell assignment that auto-approved itself. It also quietly flips CLAUDE_CODE_SUBAGENT_MODEL, which the docs still describe the old way.
Claude Code 2.1.248: a restricted mode lands, and your long sessions were losing their cache every hour
Two releases since 2.1.247, only one of them with notes, and it is a big one. The new --restricted flag strips execution and ignores your own settings files, a fix returns the prompt cache that an OAuth token refresh was dropping roughly once an hour, and locally seeded cloud sessions no longer carry your in-progress secret files with them.
Claude Code 2.1.247: Claude drafts your bug report, and you decide whether the transcript goes with it
One release, one real addition: the SendFeedback tool, which has Claude write the report you then send from /feedback. The changelog gives it a single line; the docs give a lot more, starting with the fact that the two ways to send a draft do not carry the same thing. Plus two config files the client used to clobber, and Sonnet 5 auto-compacting 33,000 tokens later.
Claude Code 2.1.246: your Bash allow rule may cover far more than it says
One release since 2.1.245, but roughly sixty entries. The most useful one is a new startup warning: a Bash allow rule with its wildcard placed before the subcommand permits much more than what you wrote. Plus a gateway credential that was going to the wrong host, and three cases where the client reported success instead of an interruption.
Claude Code 2.1.243 to 2.1.245: the one-hour prompt cache is now yours to set
After two silent releases, 2.1.243 lands with around sixty entries, including the setting every API-key user was missing: choosing your own prompt cache lifetime. Plus a Linux startup crash fix shipped the same day.
Claude Code 2.1.240 and 2.1.241: two releases, no release notes
Two shipments in two days, each carrying the same single line: "Bug fixes and reliability improvements". Nothing else. When the changelog tells you nothing, the decision that matters is no longer what to install but which channel you live on. A look at the setting almost nobody touches.
Rewriting 535,000 lines with AI agents: Bun's method, and what it doesn't prove
Bun went from Zig to Rust in 11 days with 64 Claude agents, for $165,000. The method transfers to a solo project. The four numbers everyone quotes do not.
Claude Code 2.1.239: what you were paying without seeing it, and Windows joins cross-session messaging
One release, 61 entries, and a thread that is all about money: the data residency premium finally shows up in cost estimates, a Bedrock bug was silently doubling your billed API calls, and the usage limit message now tells you when it resets. Plus cross-session messaging landing on native Windows.
Claude Code 2.1.235 to 2.1.238: what used to fail silently now tells you
Four releases in three days, 93 changelog entries, and one very clear thread running through them: a dozen fixes turn silent failures into explicit errors. Plus headersHelper landing on plugin marketplaces and a Remote Control that finally holds up.
Claude Code 2.1.234: sessions resume on their own, permission prompts get hardened
2.1.234 makes Claude Code resume your session automatically once your claude.ai usage limit resets, closes several permission bugs that could hide a dangerous command from an approver or drop a denial, and quietly changes what Esc does to a text selection.
Claude Code 2.1.233: todo tools off by default, an NTLM leak closed
2.1.233 disables task-tracking tools by default on the newest models, fixes an NTLM leak on Windows, and walks back part of 2.1.232's Bash permission changes.
Claude Code 2.1.231 and 2.1.232: Bash redirections now need permission, sandbox lockdown
Versions 2.1.231 and 2.1.232 close six sandbox and permission bypasses, put Bash < file redirections under permission checks, and turn subagent forking on by default.
Claude Code 2.1.229: /commit-push-pr gets stricter, OAuth and Windows runners fixed
2.1.229 stops /commit-push-pr from auto-approving dangerous flags, fixes MCP OAuth against strict authorization servers, and requires --base-dir for self-hosted runners on Windows, plus a batch of crash fixes.
Claude Code 2.1.228: Write changes its rule, synced skills get locked down
2.1.228 relaxes the Write tool for recent models, fixes a title leak via /resume in Remote Control, and hardens skills synced from claude.ai against command hijacking.
Claude Code 2.1.227: the bug that broke Bash under claude-code-action is fixed
2.1.227 fixes a bug that made every Bash command fail under claude-code-action on GitHub-hosted runners, plus a display glitch after rewinding in /tui.
The Best MCP Servers for Claude Code: A Ranking by Context Budget
Every MCP server costs you context before you type a word. The 2026 ranking of which servers earn their keep, and which ones quietly bankrupt you.
Claude Has No Embedding Model: What to Use Instead
Anthropic does not offer an embedding model and says so in its own docs. Voyage AI is the official pick, but not the only one. Prices and how to choose.
Claude's Tokenizer Counts 30% More Tokens: What That Actually Does to Your Bill
Since Opus 4.7, Claude splits the same text into ~30% more tokens. The sticker price never moved, your invoice did. Which models, and how to measure it.
Claude Code 2.1.225 and 2.1.226: headless OAuth token bug fixed, claude agents now asks for trust
2.1.225 fixes a bug that broke headless sessions by swapping your long-lived OAuth token for a short-lived one, and hardens cross-session messaging.
Claude Code 2.1.224: sessions can now talk to each other, a real sandbox bypass closed
2.1.224 fixes a sandbox rule silently bypassed on Linux and macOS, and adds cross-session messaging with SendMessage and ListAgents.
Claude Code 2.1.223: four permission bypasses closed, /review merges into /code-review
2.1.223 fixes four distinct ways to sneak commands past permission checks, folds /review into /code-review, and tightens 1M context window enforcement.
Claude Code 2.1.222: worktree isolation actually holds now, ultraplan is gone
2.1.222 closes an isolation gap between worktree sessions and the main checkout, fixes a tool-restriction bypass in background tasks, and drops ultraplan.
Claude Code 2.1.221: the Bash zsh permission bypass gets closed, background sessions start pushing on their own
2.1.221 fixes a real permission bypass on Bash and PowerShell, and changes background sessions to commit and push on their own by default.
Claude Code 2.1.219 and 2.1.220: Opus 5 becomes the default, subagent nesting makes a comeback
2.1.219 makes Opus 5 the default Opus model, brings back subagent nesting three levels deep, and adds a real network lock for sandboxed commands.
Claude Code 2.1.218: /code-review moves to the background, /deep-research stops launching itself
2.1.218 makes /code-review a background subagent, switches /deep-research to manual trigger only, and closes a hole on untrusted agent hooks.
Claude Code 2.1.217: Subagents No Longer Chain Automatically, and a Workspace Escape Is Patched
2.1.217 caps concurrent subagents at 20, turns off nesting by default, and fixes a symlink-based workspace escape and a startup hang risk.
Claude Code 2.1.216: Symlink Security Holes Patched, and Long Sessions Finally Stop Crawling
2.1.216 closes several symlink and git-isolation holes, fixes a quadratic slowdown in long sessions, and restores background agent identity on resume.
Claude Code 2.1.215: /verify and /code-review No Longer Run on Their Own
2.1.215 removes the automatic triggering of /verify and /code-review after a code change. You now have to type the command yourself.
Claude Code 2.1.214: The Great Permission Lockdown
2.1.214 closes about a dozen permission holes (PowerShell, Bash, Docker, files), changes what your dir/** rules match, and adds EndConversation.
Claude Code 2.1.212: /fork Now Goes Background, and Runaway Loops Finally Have a Ceiling
2.1.212 redefines /fork, caps subagents and web searches per session, and auto-backgrounds slow MCP calls. It also closes a plan mode permission hole.
Washington Pulled the Plug on Fable 5: The 18 Days That Redefined AI Sovereignty
June 2026: Washington ordered Anthropic to cut off Fable 5 and Mythos 5 for foreign nationals. A sourced timeline of the first state kill switch.
Everyone Teaches You to Use AI. Nobody Tells You How to Make Money With It
ChatGPT, Claude, 20 to 200 dollars a month. The real question isn't how to use AI, it's how to make your subscription pay for itself. Tier by tier.
Saving Tokens on Claude Code: Stop Blowing Your Quota
Burning through your Claude limit in two days? It's not a tier problem, it's a configuration problem. 7 settings to recover 50 to 60% of your quota.
Sandboxes, MCP Tunnels, Stainless: How Anthropic Is Pulling Ahead in Agentic AI
Three announcements in 48 hours. Anthropic brings execution in-house, connects agents to private systems without internet exposure, and takes OpenAI's SDK gen.
Google just debunked GEO and llms.txt. Here's why I keep using them anyway.
On May 15, 2026, Google published its first official position on optimizing for generative AI. Verdict: no llms.txt needed, plain SEO is enough.
Claude Code vs Cursor vs GitHub Copilot: which one to pick in 2026?
An honest comparison of the three top AI coding tools in 2026. Claude Code, Cursor and GitHub Copilot: pricing, context window, and which one fits you.
Claude for Small Business: how Anthropic just rattled Salesforce, Intuit and DocuSign
Anthropic launched Claude for Small Business with QuickBooks, PayPal, HubSpot and Docusign. What it changes for small teams, and why Wall Street took it badly.
The fading line: what Willison really admits about agentic engineering
Simon Willison coined the vibe coding / agentic engineering split, then admitted he no longer holds it. Addy Osmani and Amazon complete the picture.
2,541 GPT Conversations Analyzed: Why I Migrated Everything to Claude
I exported 2.5 years of ChatGPT data: 2,541 conversations, 13,250 responses, 119 Custom GPTs. The full data-driven analysis of my move to Claude Code.
Extended Thinking in Claude Code: When to Use It, When It's a Waste
A practical guide to Extended Thinking in Claude Code. Real refactoring and debugging cases, before/after benchmarks, and the token traps to avoid.
Memory and Persistence in Claude Code: The Complete Guide (CLAUDE.md, MCP Memory, Sessions)
Everything you need to know about persistence in Claude Code. CLAUDE.md, memory files, MCP Memory, session storage: which mechanism to use and when.
The Complete Anthropic Ecosystem Map (2026): SDKs, MCP, Agents, Open Source Tools
Complete guide to the Anthropic ecosystem in 2026. All SDKs, MCP servers, agent tools, and open source repos. What we actually use, what's noise.
Don't Build Agents, Build Skills (the Lesson Anthropic Teaches in 16 Minutes)
Two Anthropic engineers explain why skills beat custom agents. Summary, analysis and practical lessons from Barry Zhang and Mahesh Murag's talk.
Agent Skills: How Anthropic Created an Open Standard the Entire Industry Is Adopting (and Why It Changes Everything)
Anthropic's Agent Skills went from a Claude feature to an industry standard in two months. OpenAI is copying them, Microsoft is integrating them.
Claude Code Release Tracker: the Updates That Actually Matter (April 2026)
Monthly recap of Claude Code features that are actually game changers. Not raw changelogs: editorial analysis, real impact, and what it means for builders.
Claude Managed Agents: the Kill Switch Anthropic 'Forgot' (and Why It's Costing You)
Complete guide on Claude Managed Agents pitfalls: how tokens explode, why the kill switch is nowhere to be found, and the real safeguards to configure.
10 Custom Claude Code Agents Ready to Copy (With Full YAML)
10 production-ready Claude Code agents with full YAML configs: monitoring, code review, tests, docs, debug, migration, security. Copy, paste and adapt.
Multimodal RAG in 30 minutes: Gemini Embedding 2 + Claude Code
Google releases its first natively multimodal embedding model. Text, images, video and audio in one vector database, wired up with Claude Code.
Claude Mythos and Project Glasswing: The Model Anthropic Refuses to Release (and Why It's a Turning Point)
Claude Mythos, Anthropic's most powerful model: 93.9% on SWE-bench and thousands of zero-days found. But it won't be public. Inside Project Glasswing.
Claude Cowork: the complete guide to automating your daily work
Cowork turns Claude into an assistant that reads your files, manages your calendar and runs workflows. Folders, connectors, skills, Dispatch and scheduling.
Anthropic Cuts Off OpenClaw: Why Your AI Setup Should Never Depend on Anyone
Anthropic blocked Claude subscriptions via OpenClaw on April 4, 2026. The facts, the strategic reasons, and what it means if you build with Claude.
Claude Code's Source Code Leaked: What We Found, What's False, and Why It Matters
512,000 lines of TypeScript exposed via npm. The leak, the hidden features, and the cache bug that multiplied costs by 20x.
Claude and Claude Code FAQ: Everything You Need to Know in 2026
Answers to the most asked questions about Claude, Claude Code, Opus/Sonnet/Haiku models, pricing, MCP, and differences with ChatGPT and Gemini.
15,000$, 8 Hours, Zero Hand-Typed Lines: Anatomy of an Anthropic Hackathon Win
Affaan Mustafa won the Anthropic x Forum Ventures hackathon with Claude Code. His everything-claude-code repo reveals a new agent and memory setup.
Pillar 3: security and hosting for AI builders (OWASP, pen test, scaling)
AI doesn't think like an attacker. OWASP Top 10, pen testing, hosting, load testing, scaling: the security checklist for builders coding with AI.
Pillar 2: CI/CD and monitoring for solo builders (GitHub Actions, Sentry, uptime)
Manual deployment is the best way to ship broken code without knowing. CI/CD, Sentry, uptime monitoring: the minimum viable pipeline for solo builders.
Pillar 1: testing your AI code before shipping (TDD, unit tests, e2e)
AI generates code that works in the prompt. Not necessarily in production. Here's how to test code you didn't write: TDD, unit tests, integration, e2e.
The Checklist Before Shipping with AI: 3 pillars vibe coding ignores
You've been coding with AI for months. You ship fast. But do you test? Monitor? Secure? 3 pillars to go from vibe coding to software engineering.
How I built an AI copilot that runs my life as a solo builder
The full architecture of a Claude Code system that runs my daily operations: recaps, business tracking, content generation, monitoring and persistent memory.
The Claude Coder Paradox: why the tool that saves you time can waste it
You adopt Claude Code to move faster. Then you want to do everything, explore everything. The infinite multi-tasking trap, and how to escape it.
Prompt engineering: 5 myths you need to stop believing
Viral 'perfect prompts' are theater. Breaking down prompt engineering myths with Anthropic's official recommendations and concrete examples.
Harrison Chase is right: coding agents are redefining development
Harrison Chase's viral thread on how coding agents restructure product teams, seen by a solo builder who lives that thesis every day.
Why Claude Code is a game changer in 2026
80,000+ GitHub stars, millions of developers, and yet almost no curated resource hub. Breaking down the tool that's redefining AI-assisted development.