Claude Code Daily Briefing - 2026-08-29

Release Summary

VersionDateKey Changes
v2.1.2518/28PreModelSwitch/PostModelSwitch hooks, /usage Spend limit bar, 5 security fixes covering symlinks, plugin paths, and more
v2.1.2508/28Bug fixes and stability improvements (no separate changelog, covered in the 8/28 briefing)
v2.1.2488/27--restricted mode, cross-session messaging extended to Bedrock, Vertex, and Foundry (covered in the 8/28 briefing)

v2.1.251 (8/28) followed v2.1.250 (8/28) on the same day, arriving with a much larger changelog. Yesterday’s briefing treated v2.1.250 as a quiet patch with no changelog to speak of, but the release that followed it, v2.1.251, turns out to be the biggest security-hardening release of the week. It bundles five security fixes at once — a symlink-based file tool bypass, a plugin marketplace path-traversal escape, a Workflow tool scriptPath permission bypass, and a Grep/Glob symlink deny-rule bypass — alongside new features like PreModelSwitch/PostModelSwitch hooks, real-time subagent streaming, and the /usage Spend limit bar.

Full release notes


New Features & Practical Usage

PreModelSwitch/PostModelSwitch hooks — intercept, block, confirm, or log model switches (v2.1.251)

New PreModelSwitch and PostModelSwitch hook events let you intercept the moment a model switch happens, so you can block it, require confirmation, or just log it. Alongside this, the SessionStart resume hook was also improved to pass along the session’s staleness and the expected re-caching cost.

# Example hooks configuration
hooks:
  PreModelSwitch:
    - command: "./check-model-switch.sh"

If your sessions bounce between multiple models automatically — through fast mode switches or effort-based model branching — you can now audit or block switches to specific models with a single hook, instead of working around it after the fact. Full release notes

/usage gets a Spend limit bar, and the status line gets rate_limits.spend_limit (v2.1.251)

For developers at organizations that have set a spend limit behind the Claude apps gateway, /usage now shows a spend limit progress bar, and a rate_limits.spend_limit field is now available for status line scripts to consume as well.

If you’re working somewhere your organization manages a gateway spend limit, you can now check exactly how close you are to it directly from /usage or a custom status line, without having to ask around. Full release notes

Foreground subagent tool calls now stream live to Remote Control (v2.1.251)

Tool calls and results from subagents running in the foreground now stream live to any client connected via Remote Control (background subagents still default to showing status only, as before).

If you’re watching a session over Remote Control from your phone or the web, you can now follow exactly which tool a subagent is calling in real time, not just whether it’s running. Full release notes

Model Hardware Standard — Anthropic and HHMI Janelia’s shared standard for AI agents controlling robots and lab equipment (8/29)

Anthropic and HHMI Janelia have launched a limited research preview of the Model Hardware Standard (MHS), which connects AI agents to physical hardware such as microscopes, robotic arms, and liquid handlers. The goal is to unify the wildly different control interfaces and status reporting that each equipment vendor uses today, cutting down on the custom code teams currently have to write every time they wire up a new device.

If your team is putting Claude agents to work in lab or robotics workflows, this standard is worth watching as an alternative to building a one-off integration for every piece of equipment. GeekNews


Developer Workflow Tips

/cost adds a per-session prompt cache line (v2.1.251)

/cost now shows a line with this session’s prompt cache hit rate, misses, re-cached token count, and warm/cold status, and a prompt_cache object is now available for status line scripts to use as well.

/cost
# See cache hit rate, misses, re-cached tokens, and warm/cold status in one line

Instead of guessing why your cache hit rate dropped, you can now just check /cost and adjust your session structure based on real numbers. Full release notes

CLAUDE_CODE_SUBAGENT_MODEL now sets a default only — per-agent model: fields take precedence (v2.1.251)

Until now, CLAUDE_CODE_SUBAGENT_MODEL unconditionally overrode the model for every subagent; it now only sets a default. A model: field in an agent definition file, or a model specified at spawn time, takes precedence over the environment variable.

If you had carefully configured different models per subagent only to have the environment variable silently override them, this change makes things work as intended again. Full release notes

/effort now stores separate defaults per model (v2.1.251)

The default effort level you set with /effort is now stored separately for each model, so switching models keeps the effort setting appropriate to that model.

If you’ve been running Opus at xhigh and Sonnet at medium, you no longer have to reset effort every time you switch models. Full release notes


Security & Limitations

US court rules the Department of Defense’s Anthropic blacklist designation unlawful (8/29)

A federal court in California has ruled that the Trump administration’s designation of Anthropic as a national security risk — and its exclusion from US government work — was unlawful and constituted retaliation against constitutionally protected speech. Anthropic is reported to have clashed with the Department of Defense over the scope of military use of its technology during negotiations for a $200 million AI contract. In a 59-page order, Judge Rita Lin found the national-security supply-chain risk designation “unlawful and without basis,” and stated that national security cannot be used as a pretext to punish critics of the government.

If you’re deploying or considering Claude Code for government or defense-related work, it’s worth continuing to watch how this ruling affects the broader procurement standoff between Anthropic and the Department of Defense, since it could shape future policy. GeekNews

v2.1.251 bundles five security fixes closing permission-bypass paths

This release includes fixes for five separate paths that could be used to bypass file access and permission checks.

If you handle untrusted input or run Claude Code in a multi-user environment, all five of these fixes shrink real attack surface around permission boundaries, so there’s no reason to delay updating. Full release notes

Sandbox TLS, proxy, and credential settings, plus custom headers, now require approval (v2.1.251)

Server-managed settings that terminate sandbox TLS, reroute sandbox traffic through a custom proxy, inject credentials, or weaken sandbox isolation now require approval before they take effect. ANTHROPIC_CUSTOM_HEADERS also now requires approval when managed or project settings set headers related to credentials, org/tenant identity, routing, or API behavior — for example Authorization or Host.

If you’re in an organization where managed settings can manipulate the sandbox or request headers, it’s worth knowing that these sensitive changes no longer apply silently — they now go through a visible approval step. Full release notes

Claude service status — one Major incident on 8/28, resolved within 3 hours

Checking the official Claude Status API (status.claude.com) directly, after the four consecutive incident-free days from 8/25 to 8/28 covered in yesterday’s briefing, a new incident was logged — “Elevated errors on Claude Code and Claude Cowork” — from 17:22 to 20:21 UTC on 8/28 (roughly 2 hours 59 minutes). It was rated Major impact, attributed to an upstream cloud provider issue, and resolved through session retries.

As of the StatusGator check at 2026-08-28 23:58 UTC, user reports over the prior 24 hours stood at 5 — similar to the low level reported in yesterday’s morning figures, suggesting the actual user-facing impact of this incident was limited. Claude Status · StatusGator

Reminder — weekly 50% usage boost ends in 2 days

The weekly 50% usage boost for Claude Code ends on August 31 — that’s 2 days away. Sonnet 5’s $2 input / $10 output pricing, locked in as the permanent standard rate by the official Pricing documentation on 8/26, remains unchanged, so the boost’s expiration is the only variable left on the table.


Ecosystem & Plugins

No new MCP server, plugin, or third-party integration announcements today.


Community News


Minor Changes

All of the following are v2.1.251 items.



Interesting Projects & Tools