Claude Code Daily Briefing - 2026-08-28

Release Summary

VersionDateKey Changes
v2.1.2508/28Bug fixes and stability improvements (no separate changelog entries)
v2.1.2488/27--restricted mode, cross-session messaging expanded to Bedrock/Vertex/Foundry, experimental.cacheTtl, ~40 fixes
v2.1.2478/26SendFeedback tool, /claude-api cost-optimize, expanded Sonnet 5 auto-compaction threshold (covered in the 8/27 briefing)

v2.1.248 shipped on 8/27 right on the heels of v2.1.247 on 8/26, making this the biggest release stretch of the week. The standout new features are a --restricted safe mode that strips out command- and code-execution tools, and the expansion of cross-session messaging, and the release also bundles a security fix that stops /ultrareview from mistakenly uploading credential files. The follow-up v2.1.250 (8/28) is a quiet patch logged only as “Bug fixes and reliability improvements,” with no separate changelog.

Full release notes


New Features & Practical Usage

--restricted — a safe mode that removes command- and code-execution tools (v2.1.248)

Turning on the --restricted flag (or CLAUDE_CODE_RESTRICTED=1) removes the built-in tools that run commands or code, along with WebFetch (unless a tool is explicitly named in --tools). File tools are confined to the working directory, bypassPermissions is refused, and user, project, and local settings files are all ignored.

claude --restricted
# or via environment variable
export CLAUDE_CODE_RESTRICTED=1
claude

If you’re running Claude Code over untrusted input, or in an automation pipeline where you don’t want to grant anything beyond file read/write, there’s now a dedicated mode that shuts the command-execution path off at the source. Full release notes

Cross-session messaging expands to Bedrock, Vertex, and Foundry (v2.1.248)

SendMessage/ListAgents, which let sessions running on the same machine exchange messages, now also work on the previously unsupported Bedrock, Vertex, and Foundry environments, as well as in sessions with telemetry turned off.

If you’ve been deploying Claude Code through an enterprise cloud provider and couldn’t use cross-session messaging until now, the same workflow is available to try. Full release notes


Developer Workflow Tips

experimental.cacheTtl — set prompt cache lifetime per agent (v2.1.248)

Setting experimental.cacheTtl ("5m" or "1h") in an agent’s frontmatter lets you define a prompt cache lifetime that applies only to that agent, for cases where no subagent-specific TTL is set.

---
name: my-review-agent
experimental:
  cacheTtl: "1h"
---

Worth trying if you want to fine-tune caching per agent — longer TTLs for heavy agents you call often, shorter ones for one-off agents. Full release notes

The Workflow tool’s prompt footprint drops from 5.7k to 1k tokens (v2.1.248)

The Workflow tool’s own description used to eat up roughly 5.7k tokens of prompt space; that’s now down to about 1k tokens, with the detailed scripting reference split out into a bundled workflow-authoring skill.

If you use the Workflow tool a lot, the fixed cost that used to load into the system prompt every turn is now smaller, which stretches the same context budget further. Full release notes

Agent Behavior — a standard for documenting an agent’s recurring actions as evaluation criteria (8/28)

This open format comes out of the observation that a long-running AI agent, which makes hundreds of judgment calls along the way, is hard to evaluate from the final output alone. It has you document up front the behaviors an agent should repeatedly show during its work — what information it checks, what it decides, how it executes, and how it should recover when information is missing or something fails.

If you want to judge the quality of an agent or subagent you built with Claude Code by its process as well as its output, this approach of defining behavioral criteria up front, instead of just grading the final deliverable, is worth a look. GeekNews


Security & Limitations

/ultrareview no longer mis-uploads credential and config files (v2.1.248)

A fix landed for /ultrareview and locally seeded cloud sessions that were uploading uncommitted changes to prod.env-style files, *.tfvars files, and credential copies left behind by editors as swap, temp, or backup files (e.g. key.pem.tmp, id_rsa.swo). These files now stay on the local machine only.

If you’ve been using /ultrareview or cloud sessions on a repo that holds production config files, it’s worth checking whether uncommitted secrets may have been uploaded to the cloud before this fix. Full release notes

Claude service status — no new incidents from 8/25 through 8/28

Checking the official Claude Status API (status.claude.com) directly, after the three incidents on 8/24 covered in the 8/27 briefing, no new incidents have been logged across four straight days (8/25–8/28), and every service — claude.ai, Claude Console, Claude API, Claude Code, Cowork, and Government — shows All Systems Operational.

As of the StatusGator check (2026-08-28 01:18 UTC), user reports over the past 24 hours numbered just 5, continuing a steady decline from 24 on 8/26 → 15 on 8/27 → 5 now, suggesting the fallout from the 8/24 incident has essentially cleared. Claude Status · StatusGator

Reminder — 3 days left on the weekly 50% usage boost

Claude Code’s weekly 50% usage boost ends on August 31 — that’s 3 days out. Sonnet 5’s $2 input / $10 output pricing, locked in as permanent standard pricing via the official Pricing docs on 8/26, remains unchanged, so the weekly boost’s expiration is the one variable left to watch.


Ecosystem & Plugins

Corsair — a unified layer for managing AI agents’ external service connections and permissions (8/27)

A TypeScript library that centralizes the tools, credentials, and execution permissions an AI agent needs to call external services like Gmail, Slack, GitHub, Notion, and Stripe. You can wire Corsair MCP directly into an agent, or drop the SDK straight into an application, and it handles every service automatically.

If your MCP setup is granting Claude Code access to more and more external services, it’s worth evaluating a unified layer like this instead of managing auth and permissions separately for each one. GeekNews


Community News


Minor Changes

All of the following are from v2.1.248.



Interesting Projects & Tools