Fetching from the wire…
Tools2026-09-17 · source-backed
The release carries three security fixes mid-list: Bash commands looping over or assigning certain special shell variables now ask permission instead of running unprompted, worktree-isolated sessions refuse Bash commands with certain nested shell expansions, and MCP connection errors plus the MCP login tool description no longer display resolved secrets. That third one has a retroactive cost. Templating an API key into .mcp.json and expecting the indirection to keep it out of logs was reasonable, and any captured terminal output or shared error paste from before this build may hold the plaintext. Rotate anything that went through a ${VAR} in an MCP config and was followed by a connection failure.
Each link below shares sources, entities, or timing with this story.
One Claude Code release fixed two independent permission-check bypasses on the same day. That's the story. Version 2.1.221, shipped August 4, patches a Bash tool bypass where zsh could execute hidden commands embedded inside [[ ]] regex conditionals. The approval prompt never...
Claude Code 2.1.251 fixes checks that auto-approved commands assigning an arithmetic expression to an integer shell variable, naming OPTIND=1/0 and RANDOM=2+2. Both now prompt. The same release changes how Bash command output files are created and read back in the sandbox so a...
Waishnav/devspace (4,247 stars, v1.0.8 August 25) runs a local Node server exposing read, edit, search and shell execution over MCP, reached through a reverse proxy tunnel like Cloudflare or ngrok, with password-gated owner approval per client. The pitch is turning ChatGPT int...
v2.1.218 took dangerous-rm, background-&, and suspicious-Windows-path checks out of permission dialogs, and stopped prompting in plan mode for Bash the static analyzer can't prove read-only. /deep-research also now starts only when you invoke it. Fewer interrupts, but a model...
A GitHub repo cataloging Claude Code tips doesn't normally warrant a top story. But shanraisshan/claude-code-best-practice at 53.4K stars isn't a tips list anymore. It's the de facto reference for how an entire generation of developers is learning to work with AI coding agents...
2.1.268 had three, 2.1.269 closed a tee write bypass past Edit deny rules, 2.1.270 reverted a permission regression its own security release introduced, and now 2.1.271 has four more (Claude Code changelog). I don't read that as sloppiness. I read it as evidence that pattern-m...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.