Claude Code v2.1.292 Major Updates - stdio MCP Protocol Standardization and Subagent Effort Specification

Claude Code v2.1.292 Major Updates - stdio MCP Protocol Standardization and Subagent Effort Specification

Claude Code v2.1.292 has been released. This update includes the addition of an `effort` parameter to Agent tools, protocol changes for stdio MCP servers, and 92 other changes.
2026.10.07

This page has been translated by machine translation. View original

This is Ishikawa from the Cloud Business Division. Claude Code v2.1.292 (released 2026-10-06) has been released. In this article, I'll introduce the notable updates and share the results of testing with different effort values for the Agent tool.

The previous update article is here.

https://dev.classmethod.jp/articles/20261006-cc-updates-v2-1-291/

Update Summary

v2.1.292 includes 92 changes. In my classification: 46 fixes, 20 security, 11 improvements, 8 new features, 3 performance, 3 breaking changes, and 1 developer experience change. There are many fixes related to mod/plugin hooks, sandbox, and permissions, and 16 changes related to cloud sessions, Remote Control, Claude Tag, and Code Review.

Notable Updates

effort parameter added to the Agent tool

An effort parameter has been added to the Agent tool, allowing Claude to run sub-agents at the specified effort level. The official documentation also describes an effort field that can be specified in the frontmatter of a sub-agent definition. What was added this time is the argument passed when calling the Agent tool. The accepted values are verified in the "Testing Agent tool effort" section below.

This addition seems suited for those who want to vary the effort depending on the delegated work — such as high for heavy research and low for preliminary investigation.

--marketplace option added to claude plugin install

--marketplace <source> has been added to claude plugin install. It adds a marketplace as needed and installs plugins from that marketplace. Adding a marketplace is done under the same policy checks as claude plugin marketplace add. In claude plugin install --help for v2.1.292, it explains that <source> can be an owner/repo, a git or https URL, or a path, and that marketplaces not yet added will be added to user settings. Below is an example command (the plugin name and repository are placeholders).

claude plugin install <plugin-name> --marketplace <owner>/<repo>

I think authors who guide users through plugin installation will be able to cover both adding a marketplace and installing a plugin in a single command.

Protocol negotiation for 2026-07-28 version becomes default for stdio MCP server connections

Connections to local (stdio) MCP servers have changed to negotiate MCP protocol version 2026-07-28 by default across all installations, including Bedrock, Vertex, and Foundry. You can opt out with MCP_PROTOCOL_NEGOTIATION=legacy.

The official documentation (as of 2026-10-07) explains that querying stdio servers for the 2026-07-28 version has been gradually enabled since v2.1.285 for sessions that retrieve feature flags. Since sessions from third-party providers like Bedrock do not retrieve feature flags, this change now includes those sessions as well. The behavioral contrast is covered in the "Breaking Changes" section below.

Those using stdio MCP servers with Bedrock, Vertex, or Foundry should check whether connection behavior changes after updating.

One-shot claude -p now waits for background commands to complete

An issue where background commands were being stopped 5 seconds after the final result in one-shot claude -p and Agent SDK runs has been fixed. An issue where scheduled wake-ups were being discarded in one-shot claude -p has also been fixed, and it now waits for background commands and scheduled wake-ups.

Those who embed claude -p in CI or scripts and run commands in the background may find that commands no longer stop midway, though completion time may increase in some cases.

Fixed an issue where NO_PROXY was ignored when HTTPS_PROXY was set

An issue where NO_PROXY was being ignored for Claude Code's own API requests (sign-in, policy, feedback, artifacts) when HTTPS_PROXY was set has been fixed.

Organizations using NO_PROXY under an internal proxy to route connections should find that communications such as sign-in now follow the configured routing.

Fixed an issue where MCP tools with names longer than 128 characters caused all requests to fail

An issue where having an MCP tool with a name longer than 128 characters caused all requests to fail has been fixed. That tool will be excluded and an MCP error indicating the tool name will be displayed.

Those connecting MCP servers with tools that have long names should be able to avoid a situation where all requests fail because of a single tool.

Fixed an issue where permission prompts were bypassed when reading from UNC paths

An issue where PreToolUse hook approvals and auto mode were bypassing permission prompts for file reads from network (UNC) paths has been fixed. The CHANGELOG explicitly marks this as a security fix.

Those on Windows who handle files on network shares and automate approvals with PreToolUse hooks or auto mode should consider updating promptly.

Fixed missed detection of rm -rf with alternate path representations on Windows

An issue on Windows where rm -rf specifying the home folder or a drive using alternate representations such as 8.3 short names was not being treated as an operation that deletes them has been fixed. 8.3 short names are alternate names assigned by Windows to files and folders, consisting of a name of up to 8 characters and an extension of up to 3 characters.

For those who delegate file operations to Claude Code on Windows, this is a fix that reduces missed detection of commands that would delete home folders or drives.

Fixed an issue where sub-agents entered auto mode when auto mode was unavailable

An issue where a sub-agent definition specifying permissionMode: auto was entering auto mode even in states where auto mode cannot be used has been fixed. This applies when auto mode is disabled in settings, when the circuit breaker is active, or when using a model that does not support auto mode.

Those who specify permissionMode: auto in sub-agent definitions while disabling auto mode in settings should find that auto mode is no longer used as configured.

Update Details

New Features

  • effort parameter added to the Agent tool (see Notable Updates).
  • --marketplace <source> added to claude plugin install (see Notable Updates).
  • Environment variable CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS has been added. It allows setting a longer base delay for backoff when retrying requests that return overloaded (529).
  • The following additions were made for mods:
    • A prompt.autocomplete event has been added. Mods can hook into this event to add custom entries to the prompt field autocomplete list.
    • Prompt caching has been added to $.model.complete. prompt and system now accept text blocks, and adding cache: true to a block caches the request up to that block.
    • Workflow agents have been added as targets for the agent.spawn hook. Their run and index are also passed, allowing mods to reject workflow agents.

Improvements and Changes

  • Startup of claude -p and SDK sessions has been improved. The first turn no longer waits for responses to resources/list from HTTP/SSE MCP servers.
  • Startup has been improved for local (stdio) MCP servers that ignore new protocol checks. Servers that once took time to connect are remembered for 7 days and connected using the old method without waiting.
  • Rendering speed for long bulleted and numbered replies has been improved, with significant speedups for streaming, resizing, and redisplaying in transcripts (ctrl+o).
  • Restoration of prompt drafts cleared with Ctrl+C has been improved. Cleared prompts can now be recalled with the Up key even after sending slash commands or messages.
  • Tool input handling has been improved. Grep now accepts file_path in place of path, and Write, WebFetch, and Read now ignore some extra parameters instead of failing the call.
  • Sandbox auto-approval has been improved. When strict sandbox mode is specified via user settings, managed settings, or --settings, interpreter commands with environment variable prefixes such as FOO=bar python3 app.py are executed without prompting.
  • Routine execution via scheduled runs and Run now has changed to publish new artifacts visible only to the owner without requiring approval. Artifacts that request access to connectors and similar resources still require approval.
  • The Artifact tool listing has been improved. The number of published artifacts is now communicated to Claude, and up to 200 can be listed at once instead of 50.
  • Other improvements and changes include: the link to claude.ai settings in the usage limit message (changed to include https://), hints for /focus, guidance for stopped background agents in cloud sessions after restart, and messages for Claude in Chrome in cloud sessions on claude.ai.

Fixes (Major)

  • Fixed NO_PROXY being ignored: See Notable Updates.
  • Fixed all requests failing due to MCP tools with names longer than 128 characters: See Notable Updates.
  • Fixed claude -p stopping background commands: See Notable Updates.
  • Fixed plan mode not being restored on resume: This occurred when resuming a session from the session selection screen in claude --resume or via /resume.
  • Fixed saved scheduled tasks not firing: Fixed an issue where tasks created after /resume, /branch, or /clear did not fire, and an issue where subsequent creates and deletes were not reflected after two writes to the task file within a few milliseconds of each other.
  • Fixed /loop stopping in background sessions: Pending wake-ups were being lost when the session process restarted (e.g., after a crash), causing /loop to stop silently.
  • Fixed Grep and Glob reporting no match for unreadable targets: When a specified file or folder cannot be read, Claude now retries once or reports that it cannot be read.
  • Fixed only the first item being returned when a list is specified for PDF pages: When a list such as "6,9,15" was specified for pages, the Read tool was returning only the first item without an error. It now returns an error instructing to read pages or ranges one at a time.
  • Fixed @ mentions of text files over 256KB being silently excluded: Previously they were silently excluded. The file size and instructions to read it in parts are now communicated to Claude.
  • Fixed fullscreen mode in iTerm2 sending a full screen clear: When iTerm2 was detected, a full screen clear was being sent on every window resize and Ctrl+L. The CHANGELOG notes this may have been causing iTerm2's scrollback to fill with old pages.
  • A small but welcome fix: Fixed an issue where fast input, IME (input method) input, and decomposed accent characters were being lost while a prompt footer line was selected, and an issue where pressing ! left the line selected. For those who use Japanese input, this is a fix that should reduce cases where input was silently dropped.
  • Many other minor bugs have been fixed, including vim mode cursor movement, the /add-dir input field, /bug, /share, and /feedback submission, desktop app Send now, cloud session permissions and notifications, claude plugin validate listing, and more.

Security

  • Fixed permission prompts being bypassed when reading from UNC paths: See Notable Updates.
  • Fixed missed detection of rm -rf with alternate path representations on Windows: See Notable Updates.
  • Fixed sub-agents entering auto mode when they should not: See Notable Updates.
  • Fixed commands inside the sandbox being able to read the staging copy for /ultrareview: The target was copies of files staged for upload by /ultrareview under ~/.claude/seed-admin.
  • Fixed mid-session changes to managed sandbox read-deny paths not being applied: For read-deny paths (and user-side paths adjacent to them) that appear or change their referents mid-session, project permissions to their interior were not being revoked and credential injection from files targeted by those paths was not being stopped.
  • Fixed out-of-bounds file reads via link substitution during reading: Affects notebook and PDF reads on macOS and Windows.
  • Fixed policy plugins being removable via a tampered server-managed settings cache: While settings retrieval was failing, tampering with the on-disk cache allowed disabling built-in policy plugins or moving them out of position.
  • Fixed allowed-tools rules reactivating in later turns: When exiting auto mode or plan mode mid-turn, allowed-tools rules from skills and slash commands were reactivating in later turns.
  • Fixed claude plugin commands running before managed settings were loaded: On first run, commands such as marketplace add and install were executing before the organization's managed settings were loaded.
  • Fixed user-only skills being callable via compaction summaries: Repeated /name compaction summaries allowed Claude to call user-only skills.
  • Escape <system-reminder> tags in hook output: <system-reminder> tags written in hook output are now escaped before being passed to Claude.
  • Fixed dialogs not being shown when a plugin's tool.check hook returns allow: Tools requiring user responses (questions, plan approvals) were executing without displaying a dialog.
  • Fixed tool calls bypassing permission hooks during hooks worker restart: Tool calls made during a plugin hooks worker restart were being responded to without going through the plugin's permission hooks.
  • Additional fixes related to mod/plugin hooks have been made, including plugin interface calls during hooks worker restart, mod hooks that failed during turn interruption, rejections with reasons exceeding 4,096 characters, arguments received by tool.call hooks before misnamed parameters are repaired, guard hooks with .catch being skipped, and name conflicts between organization plugins and mods using $ names. The guidance displayed when a marketplace with a name similar to the official marketplace is declared in a settings file has also been improved.

Breaking Changes

There are 3 breaking changes. The before/after examples below are based on descriptions in the CHANGELOG and official documentation.

Protocol negotiation for the 2026-07-28 version becomes default for stdio MCP server connections

This is the default change for stdio MCP server connections introduced in Notable Updates. You can opt out with MCP_PROTOCOL_NEGOTIATION=legacy.

The official documentation states that MCP_PROTOCOL_NEGOTIATION is only effective with the v2 MCP client runtime. It also explains that in the v2 runtime, channel servers that negotiated the 2026-07-28 version cannot deliver channel messages and therefore will not be registered as channels.

Below are behavioral examples. Both before and after are based on the CHANGELOG and official documentation.

Before (up to v2.1.291):

# Sessions that do not retrieve feature flags (Bedrock, Vertex, Foundry, etc.)
stdio MCP server → Connect with legacy handshake (no 2026-07-28 version query)

After (v2.1.292 and later):

# All installations including Bedrock, Vertex, and Foundry
stdio MCP server → Query whether the 2026-07-28 version is supported
                 → Servers that support it    : Connect with 2026-07-28 version
                 → Servers that do not support it  : Connect with legacy handshake

stdio MCP servers that do not respond to the query will take time to connect once, then connect using the legacy method without waiting for 7 days (see "Improvements and Changes").

To revert to previous behavior:

MCP_PROTOCOL_NEGOTIATION=legacy claude

Conditions that count as failures in claude plugin test have expanded

In claude plugin test, expect failures inside hooks registered by tests and stub responses rejected by the engine now count as test failures instead of silently passing as successes. Below is the behavioral contrast.

Before (up to v2.1.291):

expect failure inside a hook registered by a test → Test passes (silently)
Stub response rejected by the engine              → Test passes (silently)

After (v2.1.292 and later):

expect failure inside a hook registered by a test → Test failure
Stub response rejected by the engine              → Test failure

Agent names are now limited to 256 characters

Agent names are now limited to a maximum of 256 characters. Names longer than that are rejected, and name fields in skill or plugin files exceeding 256 characters are ignored. Below is the behavioral contrast. The previous limit is not stated in the CHANGELOG.

Before (up to v2.1.291):

Agent names / name in skill and plugin files → Limit not stated in CHANGELOG

After (v2.1.292 and later):

Agent names                          → Rejected if longer than 256 characters
name in skill and plugin files → Ignored if longer than 256 characters

Cloud Sessions, Claude Tag, Code Review, and More

  • [Code Review] Fixed an issue where reviews ignored CLAUDE.md rules when a pull request edited CLAUDE.md. Reviews now use the CLAUDE.md from the base branch.
  • [Code Review] The PRs reviewed chart on the Code Review analytics screen now shows the period total, change from the previous period, and a breakdown by repository.
  • [Claude Tag] An Edit button has been added to the Allowed domains card on the channel Configure page. Enterprise administrators can open the access bundle that configures channel domains.
  • [Claude Tag] @Claude !status in a channel now reports that Claude has stopped reading untagged messages, the reason why, and that reading can resume with an @ mention.
  • [Claude Tag] The first message of a Slack thread continued with !fork has changed to a card showing the original thread, request, and requester, including a link to the original thread.
  • Additional fixes and changes have been made to cloud session routine display and notification settings, image file attachments, connector tool approval prompts, Remote Control first messages, Claude Tag thread replies, models, notifications, and spend limit input fields, and queued Code Review reviews.

Testing Agent Tool effort

An effort parameter has been added to the Agent tool, allowing Claude to run sub-agents at the specified effort level. I specified an effort level in the prompt and had the sub-agent respond.

Please call the Agent tool exactly once. Set subagent_type to general-purpose, effort to low, description to effort test, and prompt to "Please tell me your effort level." Do not use any other tools.

Checking whether Agent tool effort low works.

The sub-agent does not seem to recognize low.

Please call the Agent tool exactly once. Set subagent_type to general-purpose, effort to medium, description to effort test, and prompt to "Please tell me your effort level." Do not use any other tools.

Checking whether Agent tool effort medium works.

The sub-agent does not seem to recognize medium either. However, it reported a higher value than low. It appears that low, medium, and high are managed as numeric values.

Please call the Agent tool exactly once. Set subagent_type to general-purpose, effort to max, description to effort test, and prompt to "Please tell me your effort level." Do not use any other tools.

Checking whether Agent tool effort max works.

The sub-agent returned the expected response of max. Notably, xhigh also produced a similar response.

Please call the Agent tool exactly once. Set subagent_type to general-purpose, effort to ultra, description to effort test, and prompt to "Please tell me your effort level." Do not use any other tools.

Checking what happens when specifying Agent tool effort ultra, which is not supported by the sub-agent.

Sub-agent launch failed with an InputValidationError.

The description states that this should only be set when the user, or instructions from CLAUDE.md, skills, or similar, explicitly request that the agent or delegated work be run at a specific effort level — not set at Claude's own discretion. When not set, the agent runs at normal effort.

Since effort is recorded in both the transcript call content and the sub-agent metadata, I think it will be easy to verify after the fact whether the specified value was passed. Since the description mentions instructions from CLAUDE.md and skills, I can see a use case of writing something like "run preliminary investigation sub-agents at low" in CLAUDE.md.

Closing

v2.1.292 was a release where fixes and security fixes accounted for the majority of changes. The change to the default for stdio MCP negotiation should have limited impact in most environments, as the official documentation explains that the 2026-07-28 version is only used with servers that support it.

Those using stdio MCP servers or delegating work to sub-agents might want to update and give it a try.

References

https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md

https://code.claude.com/docs/en/changelog

https://code.claude.com/docs/en/sub-agents

https://dev.classmethod.jp/articles/20261006-cc-updates-v2-1-291/


Claudeならクラスメソッドにお任せください

クラスメソッドは、Anthropic社とリセラー契約を締結しています。各種製品ガイドから、業種別の活用法、フェーズごとのお悩み解決などサービス支援ページにまとめております。まずはご覧いただき、お気軽にご相談ください。

サービス詳細を見る

Share this article

AI白書