
Claude Code v2.1.292 Major Updates - stdio MCP Protocol Standardization and Subagent Effort Specification
This page has been translated by machine translation. View original
This is Ishikawa from the Cloud Business Division. Claude Code v2.1.292 (released 2026-10-06) has been released. In this article, I'll introduce the notable updates and share the results of testing with different effort values for the Agent tool.
The previous update article is here.
Update Summary
v2.1.292 includes 92 changes. In my classification: 46 fixes, 20 security, 11 improvements, 8 new features, 3 performance, 3 breaking changes, and 1 developer experience change. There are many fixes related to mod/plugin hooks, sandbox, and permissions, and 16 changes related to cloud sessions, Remote Control, Claude Tag, and Code Review.
Notable Updates
effort parameter added to the Agent tool
An effort parameter has been added to the Agent tool, allowing Claude to run sub-agents at the specified effort level. The official documentation also describes an effort field that can be specified in the frontmatter of a sub-agent definition. What was added this time is the argument passed when calling the Agent tool. The accepted values are verified in the "Testing Agent tool effort" section below.
This addition seems suited for those who want to vary the effort depending on the delegated work — such as high for heavy research and low for preliminary investigation.
--marketplace option added to claude plugin install
--marketplace <source> has been added to claude plugin install. It adds a marketplace as needed and installs plugins from that marketplace. Adding a marketplace is done under the same policy checks as claude plugin marketplace add. In claude plugin install --help for v2.1.292, it explains that <source> can be an owner/repo, a git or https URL, or a path, and that marketplaces not yet added will be added to user settings. Below is an example command (the plugin name and repository are placeholders).
claude plugin install <plugin-name> --marketplace <owner>/<repo>
I think authors who guide users through plugin installation will be able to cover both adding a marketplace and installing a plugin in a single command.
Protocol negotiation for 2026-07-28 version becomes default for stdio MCP server connections
Connections to local (stdio) MCP servers have changed to negotiate MCP protocol version 2026-07-28 by default across all installations, including Bedrock, Vertex, and Foundry. You can opt out with MCP_PROTOCOL_NEGOTIATION=legacy.
The official documentation (as of 2026-10-07) explains that querying stdio servers for the 2026-07-28 version has been gradually enabled since v2.1.285 for sessions that retrieve feature flags. Since sessions from third-party providers like Bedrock do not retrieve feature flags, this change now includes those sessions as well. The behavioral contrast is covered in the "Breaking Changes" section below.
Those using stdio MCP servers with Bedrock, Vertex, or Foundry should check whether connection behavior changes after updating.
One-shot claude -p now waits for background commands to complete
An issue where background commands were being stopped 5 seconds after the final result in one-shot claude -p and Agent SDK runs has been fixed. An issue where scheduled wake-ups were being discarded in one-shot claude -p has also been fixed, and it now waits for background commands and scheduled wake-ups.
Those who embed claude -p in CI or scripts and run commands in the background may find that commands no longer stop midway, though completion time may increase in some cases.
Fixed an issue where NO_PROXY was ignored when HTTPS_PROXY was set
An issue where NO_PROXY was being ignored for Claude Code's own API requests (sign-in, policy, feedback, artifacts) when HTTPS_PROXY was set has been fixed.
Organizations using NO_PROXY under an internal proxy to route connections should find that communications such as sign-in now follow the configured routing.
Fixed an issue where MCP tools with names longer than 128 characters caused all requests to fail
An issue where having an MCP tool with a name longer than 128 characters caused all requests to fail has been fixed. That tool will be excluded and an MCP error indicating the tool name will be displayed.
Those connecting MCP servers with tools that have long names should be able to avoid a situation where all requests fail because of a single tool.
Fixed an issue where permission prompts were bypassed when reading from UNC paths
An issue where PreToolUse hook approvals and auto mode were bypassing permission prompts for file reads from network (UNC) paths has been fixed. The CHANGELOG explicitly marks this as a security fix.
Those on Windows who handle files on network shares and automate approvals with PreToolUse hooks or auto mode should consider updating promptly.
Fixed missed detection of rm -rf with alternate path representations on Windows
An issue on Windows where rm -rf specifying the home folder or a drive using alternate representations such as 8.3 short names was not being treated as an operation that deletes them has been fixed. 8.3 short names are alternate names assigned by Windows to files and folders, consisting of a name of up to 8 characters and an extension of up to 3 characters.
For those who delegate file operations to Claude Code on Windows, this is a fix that reduces missed detection of commands that would delete home folders or drives.
Fixed an issue where sub-agents entered auto mode when auto mode was unavailable
An issue where a sub-agent definition specifying permissionMode: auto was entering auto mode even in states where auto mode cannot be used has been fixed. This applies when auto mode is disabled in settings, when the circuit breaker is active, or when using a model that does not support auto mode.
Those who specify permissionMode: auto in sub-agent definitions while disabling auto mode in settings should find that auto mode is no longer used as configured.
Update Details
New Features
effortparameter added to the Agent tool (see Notable Updates).--marketplace <source>added toclaude plugin install(see Notable Updates).- Environment variable
CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MShas been added. It allows setting a longer base delay for backoff when retrying requests that return overloaded (529). - The following additions were made for mods:
- A
prompt.autocompleteevent has been added. Mods can hook into this event to add custom entries to the prompt field autocomplete list. - Prompt caching has been added to
$.model.complete.promptandsystemnow accept text blocks, and addingcache: trueto a block caches the request up to that block. - Workflow agents have been added as targets for the
agent.spawnhook. Their run and index are also passed, allowing mods to reject workflow agents.
- A
Improvements and Changes
- Startup of
claude -pand SDK sessions has been improved. The first turn no longer waits for responses toresources/listfrom HTTP/SSE MCP servers. - Startup has been improved for local (stdio) MCP servers that ignore new protocol checks. Servers that once took time to connect are remembered for 7 days and connected using the old method without waiting.
- Rendering speed for long bulleted and numbered replies has been improved, with significant speedups for streaming, resizing, and redisplaying in transcripts (ctrl+o).
- Restoration of prompt drafts cleared with Ctrl+C has been improved. Cleared prompts can now be recalled with the Up key even after sending slash commands or messages.
- Tool input handling has been improved. Grep now accepts
file_pathin place ofpath, and Write, WebFetch, and Read now ignore some extra parameters instead of failing the call. - Sandbox auto-approval has been improved. When strict sandbox mode is specified via user settings, managed settings, or
--settings, interpreter commands with environment variable prefixes such asFOO=bar python3 app.pyare executed without prompting. - Routine execution via scheduled runs and Run now has changed to publish new artifacts visible only to the owner without requiring approval. Artifacts that request access to connectors and similar resources still require approval.
- The Artifact tool listing has been improved. The number of published artifacts is now communicated to Claude, and up to 200 can be listed at once instead of 50.
- Other improvements and changes include: the link to claude.ai settings in the usage limit message (changed to include https://), hints for
/focus, guidance for stopped background agents in cloud sessions after restart, and messages for Claude in Chrome in cloud sessions on claude.ai.
Fixes (Major)
- Fixed
NO_PROXYbeing ignored: See Notable Updates. - Fixed all requests failing due to MCP tools with names longer than 128 characters: See Notable Updates.
- Fixed
claude -pstopping background commands: See Notable Updates. - Fixed plan mode not being restored on resume: This occurred when resuming a session from the session selection screen in
claude --resumeor via/resume. - Fixed saved scheduled tasks not firing: Fixed an issue where tasks created after
/resume,/branch, or/cleardid not fire, and an issue where subsequent creates and deletes were not reflected after two writes to the task file within a few milliseconds of each other. - Fixed
/loopstopping in background sessions: Pending wake-ups were being lost when the session process restarted (e.g., after a crash), causing/loopto stop silently. - Fixed Grep and Glob reporting no match for unreadable targets: When a specified file or folder cannot be read, Claude now retries once or reports that it cannot be read.
- Fixed only the first item being returned when a list is specified for PDF
pages: When a list such as "6,9,15" was specified forpages, the Read tool was returning only the first item without an error. It now returns an error instructing to read pages or ranges one at a time. - Fixed @ mentions of text files over 256KB being silently excluded: Previously they were silently excluded. The file size and instructions to read it in parts are now communicated to Claude.
- Fixed fullscreen mode in iTerm2 sending a full screen clear: When iTerm2 was detected, a full screen clear was being sent on every window resize and Ctrl+L. The CHANGELOG notes this may have been causing iTerm2's scrollback to fill with old pages.
- A small but welcome fix: Fixed an issue where fast input, IME (input method) input, and decomposed accent characters were being lost while a prompt footer line was selected, and an issue where pressing
!left the line selected. For those who use Japanese input, this is a fix that should reduce cases where input was silently dropped. - Many other minor bugs have been fixed, including vim mode cursor movement, the
/add-dirinput field,/bug,/share, and/feedbacksubmission, desktop app Send now, cloud session permissions and notifications,claude plugin validatelisting, and more.
Security
- Fixed permission prompts being bypassed when reading from UNC paths: See Notable Updates.
- Fixed missed detection of
rm -rfwith alternate path representations on Windows: See Notable Updates. - Fixed sub-agents entering auto mode when they should not: See Notable Updates.
- Fixed commands inside the sandbox being able to read the staging copy for
/ultrareview: The target was copies of files staged for upload by/ultrareviewunder~/.claude/seed-admin. - Fixed mid-session changes to managed sandbox read-deny paths not being applied: For read-deny paths (and user-side paths adjacent to them) that appear or change their referents mid-session, project permissions to their interior were not being revoked and credential injection from files targeted by those paths was not being stopped.
- Fixed out-of-bounds file reads via link substitution during reading: Affects notebook and PDF reads on macOS and Windows.
- Fixed policy plugins being removable via a tampered server-managed settings cache: While settings retrieval was failing, tampering with the on-disk cache allowed disabling built-in policy plugins or moving them out of position.
- Fixed
allowed-toolsrules reactivating in later turns: When exiting auto mode or plan mode mid-turn,allowed-toolsrules from skills and slash commands were reactivating in later turns. - Fixed
claude plugincommands running before managed settings were loaded: On first run, commands such asmarketplace addandinstallwere executing before the organization's managed settings were loaded. - Fixed user-only skills being callable via compaction summaries: Repeated
/namecompaction summaries allowed Claude to call user-only skills. - Escape
<system-reminder>tags in hook output:<system-reminder>tags written in hook output are now escaped before being passed to Claude. - Fixed dialogs not being shown when a plugin's
tool.checkhook returns allow: Tools requiring user responses (questions, plan approvals) were executing without displaying a dialog. - Fixed tool calls bypassing permission hooks during hooks worker restart: Tool calls made during a plugin hooks worker restart were being responded to without going through the plugin's permission hooks.
- Additional fixes related to mod/plugin hooks have been made, including plugin interface calls during hooks worker restart, mod hooks that failed during turn interruption, rejections with reasons exceeding 4,096 characters, arguments received by
tool.callhooks before misnamed parameters are repaired, guard hooks with.catchbeing skipped, and name conflicts between organization plugins and mods using$names. The guidance displayed when a marketplace with a name similar to the official marketplace is declared in a settings file has also been improved.
Breaking Changes
There are 3 breaking changes. The before/after examples below are based on descriptions in the CHANGELOG and official documentation.
Protocol negotiation for the 2026-07-28 version becomes default for stdio MCP server connections
This is the default change for stdio MCP server connections introduced in Notable Updates. You can opt out with MCP_PROTOCOL_NEGOTIATION=legacy.
The official documentation states that MCP_PROTOCOL_NEGOTIATION is only effective with the v2 MCP client runtime. It also explains that in the v2 runtime, channel servers that negotiated the 2026-07-28 version cannot deliver channel messages and therefore will not be registered as channels.
Below are behavioral examples. Both before and after are based on the CHANGELOG and official documentation.
Before (up to v2.1.291):
# Sessions that do not retrieve feature flags (Bedrock, Vertex, Foundry, etc.)
stdio MCP server → Connect with legacy handshake (no 2026-07-28 version query)
After (v2.1.292 and later):
# All installations including Bedrock, Vertex, and Foundry
stdio MCP server → Query whether the 2026-07-28 version is supported
→ Servers that support it : Connect with 2026-07-28 version
→ Servers that do not support it : Connect with legacy handshake
stdio MCP servers that do not respond to the query will take time to connect once, then connect using the legacy method without waiting for 7 days (see "Improvements and Changes").
To revert to previous behavior:
MCP_PROTOCOL_NEGOTIATION=legacy claude
Conditions that count as failures in claude plugin test have expanded
In claude plugin test, expect failures inside hooks registered by tests and stub responses rejected by the engine now count as test failures instead of silently passing as successes. Below is the behavioral contrast.
Before (up to v2.1.291):
expect failure inside a hook registered by a test → Test passes (silently)
Stub response rejected by the engine → Test passes (silently)
After (v2.1.292 and later):
expect failure inside a hook registered by a test → Test failure
Stub response rejected by the engine → Test failure
Agent names are now limited to 256 characters
Agent names are now limited to a maximum of 256 characters. Names longer than that are rejected, and name fields in skill or plugin files exceeding 256 characters are ignored. Below is the behavioral contrast. The previous limit is not stated in the CHANGELOG.
Before (up to v2.1.291):
Agent names / name in skill and plugin files → Limit not stated in CHANGELOG
After (v2.1.292 and later):
Agent names → Rejected if longer than 256 characters
name in skill and plugin files → Ignored if longer than 256 characters
Cloud Sessions, Claude Tag, Code Review, and More
- [Code Review] Fixed an issue where reviews ignored CLAUDE.md rules when a pull request edited CLAUDE.md. Reviews now use the CLAUDE.md from the base branch.
- [Code Review] The PRs reviewed chart on the Code Review analytics screen now shows the period total, change from the previous period, and a breakdown by repository.
- [Claude Tag] An Edit button has been added to the Allowed domains card on the channel Configure page. Enterprise administrators can open the access bundle that configures channel domains.
- [Claude Tag]
@Claude !statusin a channel now reports that Claude has stopped reading untagged messages, the reason why, and that reading can resume with an @ mention. - [Claude Tag] The first message of a Slack thread continued with
!forkhas changed to a card showing the original thread, request, and requester, including a link to the original thread. - Additional fixes and changes have been made to cloud session routine display and notification settings, image file attachments, connector tool approval prompts, Remote Control first messages, Claude Tag thread replies, models, notifications, and spend limit input fields, and queued Code Review reviews.
Testing Agent Tool effort
An effort parameter has been added to the Agent tool, allowing Claude to run sub-agents at the specified effort level. I specified an effort level in the prompt and had the sub-agent respond.
Please call the Agent tool exactly once. Set subagent_type to general-purpose, effort to low, description to effort test, and prompt to "Please tell me your effort level." Do not use any other tools.
Checking whether Agent tool effort low works.

The sub-agent does not seem to recognize low.
Please call the Agent tool exactly once. Set subagent_type to general-purpose, effort to medium, description to effort test, and prompt to "Please tell me your effort level." Do not use any other tools.
Checking whether Agent tool effort medium works.

The sub-agent does not seem to recognize medium either. However, it reported a higher value than low. It appears that low, medium, and high are managed as numeric values.
Please call the Agent tool exactly once. Set subagent_type to general-purpose, effort to max, description to effort test, and prompt to "Please tell me your effort level." Do not use any other tools.
Checking whether Agent tool effort max works.

The sub-agent returned the expected response of max. Notably, xhigh also produced a similar response.
Please call the Agent tool exactly once. Set subagent_type to general-purpose, effort to ultra, description to effort test, and prompt to "Please tell me your effort level." Do not use any other tools.
Checking what happens when specifying Agent tool effort ultra, which is not supported by the sub-agent.

Sub-agent launch failed with an InputValidationError.
The description states that this should only be set when the user, or instructions from CLAUDE.md, skills, or similar, explicitly request that the agent or delegated work be run at a specific effort level — not set at Claude's own discretion. When not set, the agent runs at normal effort.
Since effort is recorded in both the transcript call content and the sub-agent metadata, I think it will be easy to verify after the fact whether the specified value was passed. Since the description mentions instructions from CLAUDE.md and skills, I can see a use case of writing something like "run preliminary investigation sub-agents at low" in CLAUDE.md.
Closing
v2.1.292 was a release where fixes and security fixes accounted for the majority of changes. The change to the default for stdio MCP negotiation should have limited impact in most environments, as the official documentation explains that the 2026-07-28 version is only used with servers that support it.
Those using stdio MCP servers or delegating work to sub-agents might want to update and give it a try.
References
