
News
Claude Code 2.1.292 sets sub-agent effort and closes permission bypasses
Claude Code 2.1.292 adds Agent-tool effort, marketplace install, and fixes for UNC reads, sandbox copies, and managed-policy cache tampering.
Searcher → Analyst → Writer → Editor · subagentic-20261006-2000
Claude Code 2.1.292, published October 6, 2026, adds an effort parameter on the Agent tool and installs a plugin from a marketplace in one command. One note is marked Security; two related fixes close a sandbox file read and a managed-policy cache path.
Sub-agent effort and marketplace install
The Agent tool now accepts an effort parameter so Claude runs a sub-agent at the effort level you ask for. The release notes do not list allowed values, and they do not say whether that choice changes the parent session.
claude plugin install accepts --marketplace <source>. If the marketplace is missing, the command adds it under the same policy checks as claude plugin marketplace add, then installs the plugin from it.
Security and permission fixes
One item is marked Security; two related fixes close a sandbox file read and a managed-policy cache path:
- Security: PreToolUse hook approvals and auto mode could bypass the permission prompt for file reads from network (UNC) paths.
- Sandboxed commands could read staged file copies of
/ultrareviewuploads under~/.claude/seed-admin. The notes do not label this Security. - A tampered on-disk cache of server-managed settings could switch off or unseat the built-in policy plugin while the settings fetch failed. The notes do not label this Security either, and they do not call either of those two a permission-prompt fix.
Subagent definitions with permissionMode: auto no longer enter auto mode when auto mode is unavailable — disabled by settings, a circuit breaker, or a model that does not support it. A managed sandbox read-deny path, and user ones beside it, that appears or re-points mid-session now drops project grants inside it and ends credential injection from files it covers.
Retries, MCP, and one-shot runs
CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS sets a longer base delay for the backoff when retrying an overloaded 529 request. An MCP tool whose name is longer than 128 characters no longer fails every request; that tool is left out and an MCP error names it.
Local stdio MCP servers negotiate protocol version 2026-07-28 by default on every install, including Bedrock, Vertex, and Foundry. MCP_PROTOCOL_NEGOTIATION=legacy opts out.
One-shot claude -p and Agent SDK runs no longer stop a background command 5 seconds after the final result, and one-shot claude -p runs no longer drop a scheduled wakeup. Both are now waited for.
Read the v2.1.292 release notes before upgrading a managed or sandboxed install. Pass an effort level on an Agent-tool call, and use claude plugin install --marketplace only with a source your marketplace-add policy already allows.