
Claude Code v2.1.286 Major Updates - Changes to --bare and npm Source Restrictions for Plugins
This page has been translated by machine translation. View original
This is Ishikawa from the Cloud Business Division. Claude Code v2.1.286 (released UTC September 30, 2026) has been released. Since it includes changes that affect existing usage, I feel this is a release worth reading through before updating. Today, I tried out the plugin npm source restrictions.
The previous update article is here.
Update Summary
v2.1.286 includes 88 changes. In this article's classification, there are 45 fixes, 19 improvements, 7 new features, 7 breaking changes, 6 security updates, and more, with bug fixes accounting for more than half. In addition to the CLI itself, changes to the VS Code extension, cloud sessions, and Claude Tag are also included.
Notable Updates
--bare Behavior Change (Breaking Change)
When --bare is specified, it now connects only to MCP servers specified on the command line. Additionally, it no longer sends system reminders to the model and does not start background tasks. Also, with --bare, shell commands that reach a timeout now stop instead of moving to the background.
If you use --bare in CI or scripts and rely on tools from MCP servers not specified on the command line, behavior will change, so I recommend reviewing your invocation methods.
Plugin npm Source Restrictions (Breaking Change)
When installing plugins, npm sources pointing to git repositories or folders are now rejected. Plugin dependencies are also installed only from registry packages.
If you distribute plugins internally using npm sources, I recommend verifying that the specifications are for registry packages before updating.
VS Code Extension Bookmarks
A bookmark feature has been added to the VS Code extension. You can save Claude's responses and display them in the Bookmarks side panel.
For those who work with long conversations in VS Code, I find this convenient as it lets you keep responses you want to reference later close at hand.
verify Skill Execution Before Commits
If there is a skill named verify in the project or user skills, Claude is now instructed to run it just before committing. Commits containing only documentation or only tests are excluded.
If you organize your test and lint steps into a skill named verify, I feel it becomes easier to tell Claude what checks you want run before committing.
Fix for History Loss with --resume / --continue
A bug has been fixed where claude --resume and --continue could lose all turns after parallel tool calls if the previous session had crashed or been forcefully terminated.
I feel this fix reduces the concern of losing history when resuming after a session was abnormally interrupted during long tasks with parallel tool calls.
Retry When Model Is Rejected
A bug has been fixed where all turns would fail if the Anthropic API rejected the default model or the model an alias resolves to. Claude Code will now retry once with the previous model in the same tier.
I think this is a fix that prevents work from stopping for those who rely on the default model or aliases, though it's worth knowing that responses may continue with the previous model.
Fix for Credential Masking in Error Messages and Logs
Four bugs were fixed where credentials or secrets were being exposed.
- A bug where credential values appeared in MCP error messages when "Bearer" or "Basic" preceded the key name
- A bug where percent-encoded Bearer tokens were only partially masked in error messages
- A bug where secrets containing invisible characters such as zero-width spaces in key names appeared in masked logs and transcripts
- A bug where parts of passwords in URLs containing
), quotation marks,],&, a second@, etc. appeared in logs and transcripts
I think this is a fix that reduces the risk of credentials being included for those who share MCP server error messages, logs, or transcripts in inquiries. I still recommend visually checking before sharing.
Disconnection of Remote Control Disabled by Organization Policy
A bug has been fixed where Remote Control sessions (including claude remote-control) remained connected even after Remote Control was disabled by organization policy. A notification is displayed and the session is disconnected.
Administrators who manage Remote Control through organization policy should be aware that the disable setting now takes effect on active sessions as well.
Update Details
New Features
- When multiple permission requests are queued, the permission prompt now shows a count like "2 of 5."
- The "N more" line in fullscreen mode lists now supports mouse operations. Clicking moves to that end of the list, with hover and press states displayed.
- A bookmark feature has been added to the VS Code extension, allowing you to save Claude's responses and display them in the Bookmarks side panel.
- In the VS Code extension, Claude's questions and user answers are now retained in the conversation. When you respond to a question card, a Questions line is displayed showing each question and the selected content.
- A preview has been added to question cards in the VS Code extension's chat panel, showing mockups or snippets of the selected option alongside or below the choices.
- In the VS Code extension, a row has been added below messages to open terminal output, browser tabs, browser instructions, and selected code that were sent along with the message.
- An Add channel button has been added to the Claude Tag usage limits page in admin settings. You can set limits for any channel, including private channels, using a channel ID or Slack link.
Improvements
- If there is a skill named
verifyin the project or user skills, Claude is now instructed to run it just before committing (except for documentation-only or test-only commits). - Send now (ctrl+enter) in the subagent view now moves the subagent's running command to the background, so messages are read immediately.
- Commands are now displayed framed by dashed lines in Bash, PowerShell, and Monitor permission prompts (matching the display of file editing prompts).
- The external editor (Ctrl+G) now opens at the line where the cursor is positioned in the prompt, for editors that accept line numbers.
- Responsiveness of slash command suggestions while typing has been improved when many skills or plugin commands are installed. Command descriptions are matched by word prefix.
- Model fallback notifications and autocompact-thrashing errors now indicate when a fallback has reduced the context window from 1M to 200K tokens.
/hooksnow opens with a single list organized by event showing configured hooks, reducing the required Enter presses from 3 to 1.- Additionally, improvements have been made to the appearance consistency of permission prompts for fetch and skills, list screen display, handling of skill shell commands with the send-now key, cloud session routine display, and titles of sessions started from Slack.
Security
In addition to the Remote Control disconnection and four credential masking fixes introduced in the notable updates, the following changes are included.
- When loading claude.ai artifact links, WebFetch now performs the same confirmation as the Artifact tool's read operation (no confirmation while session network access is enabled, once per artifact while disabled). Also, auto mode approval is no longer treated as valid for confirmations that only the user themselves can answer.
Fixes
- Fixed history loss with
--resume/--continue: All turns after parallel tool calls could be lost if the previous session had crashed or been forcefully terminated. - Fixed all turns failing when model is rejected: Now retries once with the previous model in the same tier.
- Fixed multiple browsers opening on
gcpAuthRefresh/awsAuthRefreshexpiration: When credentials expired, multiple Claude Code processes and IDE extensions were each opening a browser for login. - Fixed API 400 errors from tool or hook return values: This occurred after objects, numbers, or booleans were returned instead of text (including in resumed sessions).
- Fixed auth method display in
claude auth status: It was reporting API keys saved via Console sign-in asclaude.ai. They are now reported asapi_key, and the VS Code extension also treats those sessions as API key sessions. - Fixed MCP connector tools not appearing: Tools were not listed for up to a day after a server deprecated the old MCP handshake.
- Fixed task management tools being unavailable in foreground subagents: In sessions where task management tools (TaskCreate/Get/Update/List, TodoWrite) were enabled, these tools were sometimes unusable.
- Fixed CLAUDE.md reload by worktree-isolated subagents: During initial file loading, the project's CLAUDE.md and its imports were being re-read from the worktree copy.
- A quietly welcome fix: A bug has been fixed where typing
/compact,/clear, or/rewindwhile viewing a background agent or teammate's transcript would execute against the main conversation without any display. It now asks for confirmation in a dialog indicating the target. I find it quietly welcome that this prevents accidentally clearing the main conversation while looking at a background agent's screen. - Additionally, numerous minor bugs have been fixed in Remote Control, subagents, the VS Code extension, cloud sessions, Claude Tag, and more.
Breaking Changes and Deprecations
In this article, the following 7 items are treated as changes that affect existing usage. Note that there are no deprecation notices in the CHANGELOG.
--bare Behavior Change
Starting with v2.1.286, --bare behaves as follows.
- Connects only to MCP servers specified on the command line
- Does not send system reminders to the model
- Does not start background tasks
- Shell commands that reach a timeout stop instead of moving to the background
Based on the CHANGELOG entry, I infer that prior to this change, it also connected to MCP servers not specified on the command line. In the claude --help description of --bare in v2.1.286, --mcp-config is listed as one way to explicitly pass context. Below is a configuration example.
Before the change (up to v2.1.285):
# Example: Running --bare without specifying MCP servers on the command line
claude --bare -p "Summarize the list of issues"
After the change (v2.1.286 and later):
# Example: MCP servers used with --bare are explicitly specified via --mcp-config
claude --bare --mcp-config ./mcp.json -p "Summarize the list of issues"
Plugin npm Source Restrictions
When installing plugins, npm sources pointing to git repositories or folders are now rejected, and plugin dependencies are installed only from registry packages. The following is a configuration example based on the npm plugin source format in the official documentation (Marketplace reference). Specific specification formats for git repositories and folders are not described in the CHANGELOG, so placeholders are used.
Before the change (up to v2.1.285):
{
"name": "formatter",
"source": {
"source": "npm",
"package": "<specification pointing to a git repository or folder>"
}
}
After the change (v2.1.286 and later):
{
"name": "formatter",
"source": {
"source": "npm",
"package": "@your-org/formatter",
"version": "^2.0.0"
}
}
Note that the official documentation provides github and url as plugin sources for fetching plugins from git repositories.
VS Code Extension Stop / Escape
| Operation | Before the change (up to v2.1.285) | After the change (v2.1.286 and later) |
|---|---|---|
| Stop / Escape | Ends the current turn (I read this as also stopping background agents, but this is my inference) | Ends only the current turn; background agents continue running |
| Stopping background agents | Not described in CHANGELOG | Can be stopped one by one from the agent map |
API Request Retry Limit
| Item | Before the change (up to v2.1.285) | After the change (v2.1.286 and later) |
|---|---|---|
| Unit of retry limit | I read this as not being per entire model call (inference) | One limit per entire model call |
| Maximum requests sent by a failing call with default retry settings | Not described in CHANGELOG | 14 times |
Browser Link Removal from /ultrareview Output
| Target | Before the change (up to v2.1.285) | After the change (v2.1.286 and later) |
|---|---|---|
/ultrareview and claude ultrareview output |
Includes browser link | Does not include browser link |
Number Keys in Output Style / Theme Selection Screens
| Screen | Before the change (up to v2.1.285) | After the change (v2.1.286 and later) |
|---|---|---|
| Output style selection screen | Can select style with number keys | Cannot select with number keys. Opens with current style instead of Default, with each style's description shown on the line below the name |
| Theme selection screen | Can select theme with number keys | Cannot select with number keys. Becomes a scrollable list that fits in the terminal without pushing the preview off screen |
Trying Out Plugin npm Source Restrictions
In Claude Code v2.1.286, npm sources pointing to git repositories or folders are now rejected when installing plugins. In this hands-on, I'll create a local test marketplace and verify that installing plugins with npm sources pointing to a folder or git repository is rejected.
- What to verify: Define 3 plugin entries in the same marketplace and confirm that a relative path source can be installed, while npm sources pointing to a folder or git repository are rejected at install time
- Impact on normal settings: Since
CLAUDE_CONFIG_DIRis used to redirect the config directory to a temporary directory, nothing is written to the~/.claudeconfiguration
Overall Flow
Define and install the following 3 entries in a test marketplace.
| Entry name | Source | Specification content |
|---|---|---|
hello-relative |
Relative path | Folder inside the marketplace ./plugins/hello-plugin |
hello-npm-folder |
npm | Folder specification starting with file: |
hello-npm-github |
npm | Git repository specification starting with github: |
Step 1: Prepare the Working Directory and Config Directory
Create a temporary directory, navigate to it, and point CLAUDE_CONFIG_DIR to a subdirectory within it. CLAUDE_CONFIG_DIR is an environment variable that changes the directory where Claude Code saves configuration, plugins, etc. (default is ~/.claude). Only claude commands run in a shell with this variable set will use the configuration in the temporary directory.
% WORK="$(mktemp -d)" && cd "$WORK"
% export CLAUDE_CONFIG_DIR="$WORK/claude-config"
Step 2: Create a Test Plugin
Create a plugin hello-plugin with a single skill inside the marketplace folder.
% mkdir -p test-marketplace/.claude-plugin \
test-marketplace/plugins/hello-plugin/.claude-plugin \
test-marketplace/plugins/hello-plugin/skills/hello
% cat > test-marketplace/plugins/hello-plugin/.claude-plugin/plugin.json <<'EOF'
{
"name": "hello-plugin",
"description": "A greeting plugin for the npm source hands-on",
"version": "1.0.0",
"author": { "name": "Your Name" }
}
EOF
% cat > test-marketplace/plugins/hello-plugin/skills/hello/SKILL.md <<'EOF'
---
name: hello
description: Greet the user
---
Greet the user in one short sentence.
EOF
The following files and directories were created.
% tree -a
.
└── test-marketplace
├── .claude-plugin
│ └── marketplace.json
└── plugins
└── hello-plugin
├── .claude-plugin
│ └── plugin.json
└── skills
└── hello
└── SKILL.md
Step 3: Define and Validate the Marketplace
Create a marketplace.json with 3 entries. Since the absolute path of the folder created in Step 2 needs to be inserted as the file: value for hello-npm-folder, only this heredoc uses <<EOF (without quotes) to expand $WORK.
% cat > test-marketplace/.claude-plugin/marketplace.json <<EOF
{
"name": "test-marketplace",
"description": "Hands-on marketplace for npm source restrictions",
"owner": { "name": "Your Name" },
"plugins": [
{ "name": "hello-relative", "source": "./plugins/hello-plugin" },
{ "name": "hello-npm-folder", "source": { "source": "npm", "package": "file:$WORK/test-marketplace/plugins/hello-plugin" } },
{ "name": "hello-npm-github", "source": { "source": "npm", "package": "github:your-org/hello-plugin" } }
]
}
EOF
$ claude plugin validate ./test-marketplace
Validating marketplace manifest:
/private/var/folders/pk/lwtwfbyd5svbgb_4jry_tghr0000gn/T/tmp.o2uD2yfNEn/test-marketplace/.claude-plugin/marketplace.json
✔ Validation passed
Validation passes. npm sources pointing to folders or git repositories do not cause errors at this stage (in the output below, the temporary directory path has been replaced with $WORK. On macOS, this path is displayed with /private prepended).
Step 4: Register the Marketplace and Install the 3 Plugins
Marketplace registration and installation of hello-relative succeed. "user settings" in the output refers to the configuration file in the temporary directory switched to in Step 1.
% claude plugin marketplace add ./test-marketplace
✔ Successfully added marketplace: test-marketplace (declared in user settings)
% claude plugin install hello-relative@test-marketplace
✔ Successfully installed plugin: hello-relative@test-marketplace (scope: user)
hello-npm-folder and hello-npm-github are rejected and exit with code 1.
% claude plugin install hello-npm-folder@test-marketplace
Installing plugin "hello-npm-folder@test-marketplace"...
✘ Failed to install plugin "hello-npm-folder@test-marketplace": "file:/var/folders/pk/lwtwfbyd5svbgb_4jry_tghr0000gn/T/tmp.o2uD2yfNEn/test-marketplace/plugins/hello-plugin" was not installed: it is not an http or https link. An npm plugin source must name a registry package (name or name@version) or link to a tarball file. For a plugin in a git repository, use a "github", "url" or "git-subdir" source.
% claude plugin install hello-npm-github@test-marketplace
Installing plugin "hello-npm-github@test-marketplace"...
✘ Failed to install plugin "hello-npm-github@test-marketplace": "github:your-org/hello-plugin" was not installed: it is not an http or https link. An npm plugin source must name a registry package (name or name@version) or link to a tarball file. For a plugin in a git repository, use a "github", "url" or "git-subdir" source.
The message indicates that npm sources can only specify a registry package (name or name@version) or a link to a tarball file, and that github, url, or git-subdir sources should be used for git repository plugins.
Step 5: Verify Installed Plugins
% claude plugin list
Installed plugins:
❯ hello-relative@test-marketplace
Version: 1.0.0
Scope: user
Status: ✔ enabled
Only hello-relative is installed.
Supplement: Removing the Tested Plugin
Removing the marketplace registration also uninstalls plugins installed from it. Finally, unset the environment variable and delete the temporary directory.
% claude plugin marketplace remove test-marketplace
unset CLAUDE_CONFIG_DIR
cd ~ && rm -rf "${WORK:?}"
✔ Successfully removed marketplace: test-marketplace
Also uninstalled 1 plugin from this marketplace:
hello-relative@test-marketplace
The removal also deletes their saved options, secrets and data where it can.
To use a plugin again, add the marketplace back and reinstall the plugin.
Results Summary
| Entry name | Source | claude plugin validate |
claude plugin install |
|---|---|---|---|
hello-relative |
Relative path | Passed | Succeeded |
hello-npm-folder |
npm (file: folder specification) |
Passed | Rejected (exit code 1) |
hello-npm-github |
npm (github: git repository specification) |
Passed | Rejected (exit code 1) |
claude plugin validatedoes not error on npm sources pointing to folders or git repositories. Rejection occurs at install time.- In my environment, git repository specifications beginning with
git+https://were also rejected with the same message as above. - The change mentioned in the CHANGELOG regarding "plugin dependencies are installed only from registry packages" was not verified in this hands-on.
Closing
The VS Code bookmarks and the change to instruct Claude to run a skill named verify just before committing left an impression as changes relevant to daily work. With 7 breaking changes, which is on the higher side, I intend to understand the contents before updating.
For those involved in --bare scripts or plugin distribution, I encourage you to review the breaking changes section and then try updating.
References
