Claude Code Daily Briefing - 2026-08-13

Release Summary

VersionDateKey Changes
v2.1.2298/12Plugin marketplace command source, server-supplied hooks for self-hosted runners, gateway SSE keep-alive, removal of auto-approval for risky /commit-push-pr flags, and more
v2.1.2288/11Hardened claude.ai sync skill security, Write tool policy changes (covered in the 8/12 briefing)
v2.1.2278/10Fixed a Fable credit false-positive prompt, fixed a total Bash failure in claude-code-action (covered in the 8/11 briefing)

The pure-hardening streak running through v2.1.227 (8/10) and v2.1.228 (8/11) — two straight days with zero Added entries — broke again with v2.1.229 (8/12). Four Added entries landed at once: a plugin marketplace command source, server-supplied hooks for self-hosted runners, gateway SSE keep-alive, and cross-machine session state labeling. Still, most of the changelog remains around 20 Fixed entries, making this more of a hybrid release that mixes new features with hardening.

Full release notes


New Features & Practical Usage

Plugin marketplace command source — a local command’s plugin directory is re-resolved every session (v2.1.229)

The plugin marketplace now supports a command source. When a local command (e.g., from your IDE) prints out a plugin directory, that path gets re-resolved every session and takes effect immediately, with no restart required. With mode: "link", that directory is used in place, as-is.

// Specifying a command source in a marketplace definition.
// The local command must print the plugin directory path to stdout.
{
  "source": "command",
  "command": "my-ide-plugin-path",
  "mode": "link"
}

This adds yet another plugin distribution path, following the 8/8 archive source (single-zip offline distribution) and the 8/6 owner/* wildcard. What sets this one apart is that the source is a running local command rather than a static file — an IDE or internal tool can dynamically report the currently active plugin set, re-evaluated every session, which fits workflows where you’re iterating on a plugin under development and want to keep testing changes without restarting. Full release notes

Self-hosted runners now support server-supplied hooks (v2.1.229)

claude self-hosted-runner, introduced on 8/8, now supports Claude Code hooks supplied directly by the server — bringing hook behavior in line with what managed environments (cloud sessions run by Anthropic) already had.

Until now, self-hosted runners lagged a step behind managed environments in this respect. Organizations could enforce server-defined hooks (e.g., pre-commit validation, pre-deploy gates) on managed sessions, but had no equivalent way to apply the same policy to sessions running on their own runners. That gap is now closed. If your team is on a Team or Enterprise plan and already running self-hosted runners, it’s worth checking that your server-side hook policies now apply consistently to runner sessions too. Full release notes

SSE keep-alive pings added to gateway streaming — prevents idle timeouts on Vertex and Bedrock (v2.1.229)

Gateway streaming responses now send SSE keep-alive pings during long thinking segments, preventing connections from being dropped by idle timeouts on Vertex AI and Bedrock upstreams.

The more complex the task, the longer the model tends to think — and when nothing flows through the stream during that stretch, intermediate proxies or load balancers would sometimes drop the connection. If your organization routes through Vertex or Bedrock as a gateway, this fix may resolve some of those unexplained mid-task disconnects during long reasoning runs. Full release notes


Developer Workflow Tips

claude remote-control --continue — instantly resume your most recent Remote Control session (v2.1.229)

claude remote-control --continue

This shortcut for resuming your most recent Remote Control session is now officially documented. If you’re using the cross-session messaging and SendMessage features covered in the 8/8–8/9 briefings to hop between sessions across machines, you can now jump straight back in with this one line instead of hunting down which session it was.

VS Code sidebar session groups — manage multiple sessions together (v2.1.229)

The VS Code extension’s sidebar now supports session groups. You can right-click to create, rename, or delete a group, and use Cmd/Ctrl-click or Shift-click to move multiple sessions into a different group at once.

If you’re in the habit of running several sessions at once, this is an immediately noticeable change. Until now, the sidebar just kept growing into one long list as sessions piled up — now grouping sessions by project or task makes it much faster to find which session was for what. Like the self-hosted runners from 8/8 and cross-session messaging from 8/9, this UI improvement tracks the broader trend of people running more and more sessions in parallel. Full release notes

Workflow fan-out staggering — sibling agents with a shared prefix reuse the cache (v2.1.229)

In workflow fan-out, sibling agents that share the same prompt prefix now start slightly staggered, so that agents starting later can read the cached prompt prefix instead of paying for it again. You can disable this with CLAUDE_CODE_WORKFLOW_PREFIX_STAGGER_MS=0.

If you regularly fan out dozens of agents at once with the Workflow tool, you may see a modest drop in token cost with no configuration needed. That said, if you’re running a benchmark-style task that depends on agents starting at exactly the same instant, this staggering could throw off your timing — in that case, it’s safer to disable it via the environment variable. Full release notes


Security & Limitations

Claude incident — seven-day incident-free streak broken by an 8/12 Fable 5 performance degradation

Per the official Claude Status page (status.claude.com), right after the 8/12 briefing noted “no new incidents for seven days since 8/5,” a new incident hit that same afternoon.

All systems are currently operational, and StatusGator’s check at 2026-08-13 01:38 UTC also shows normal status. Self-reported issues over the past 24 hours are back down to 21, following the 12,583 logged on 8/12 (presumably counted on a different basis).

Separate from the recurring discussion in the 8/8–8/12 briefings about “human threat-detection accuracy sitting at just 66.3%” and “auto mode’s classifier still leaving 11% residual risk,” this incident was a straightforward model performance degradation. If you’re running Fable 5 in a production pipeline, it’s worth checking whether any requests processed between 13:50 and 18:07 UTC on 8/12 came back with degraded quality. Claude Status · StatusGator

/commit-push-pr no longer auto-approves risky git/gh flags (v2.1.229)

The /commit-push-pr command now excludes git/gh invocations containing risky flags like --force, --amend, and --no-verify from auto-approval.

Previously, if this command was covered by an auto-approval rule, even hard-to-reverse operations like force pushes or commit amends could slip through without a separate confirmation. This fix runs in the same direction as the human-approval accuracy study (11.7% miss rate on destructive commands) from the 8/8 briefing and the auto mode classifier debate from 8/9 — the more irreversible an operation is, the more it warrants an extra layer of explicit confirmation, even when it matches an auto-approval rule. If your team has /commit-push-pr on its auto-approval list, note that calls containing risky flags will now require confirmation again. Full release notes

Sandbox network domain list — IPv6 notation now requires brackets and fails closed (v2.1.229)

IPv6 literals in the sandbox network domain list must now be bracketed, like [::1]:443; ambiguous notation now fails closed (is blocked), and /doctor flags this for you.

This is the same family of fix as the trailing-slash bypass in sandbox filesystem block rules covered in the 8/9 briefing — a path where ambiguous notation could unintentionally defeat a rule, this time closed off for IPv6 address notation. If your sandbox network policy explicitly lists IPv6 addresses, it’s worth running /doctor once to check for warnings. Full release notes

Reminder — auto mode default switch lands tomorrow (8/14, D-1); Sonnet 5 launch pricing ends D-18

The auto mode default switch covered in the 8/9–8/12 briefings is now just a day away (8/14) — today is your last chance to check your settings. If you’re on a Pro, Max, or Team plan, it’s worth opening /config today to review your approval settings and deny rules. Sonnet 5’s launch pricing ends on 8/31, after which input/output prices rise to $3/$15 (+50%) starting 9/1 — that’s D-18.


Ecosystem & Plugins

Delta — a multiplayer environment for coding and reviewing alongside agents enters private beta (8/13)

Delta, an environment where developers and agents share the context of both code and conversation while reviewing implementation results together, has opened its first private beta to users. Its defining feature: DeltaDB replicates conversations and work trees in real time, recording the changes and discussion that happen between commits, while keeping your existing Git repository’s commit/push flow completely intact.

This lands on exactly the same problem the 8/6–8/7 briefings covered with Zed’s DeltaDB and Jujutsu — the limitation that a commit only records “what changed,” losing the conversational context of “why it changed this way.” Delta’s approach is to replicate the conversation and work tree themselves in real time, like a repository. If you’ve ever been frustrated watching discussions with an agent vanish from the commit log, this is worth a look. GeekNews


Minor Changes

All of the following are from v2.1.229.



Interesting Projects & Tools