Claude Code 2.1.289 fixes Read-deny bypasses via file references and symlinks
Claude Code 2.1.289 fixes file references and symlinks bypassing Read deny rules. It also addresses managed approval issues and adds teammate agent spawning.

TL;DR
- File-read restrictions now cover more entry points: ClaudeCodeLog's announcement reports repaired
Readdeny enforcement for@references and symlink-related IDE access. - Bash deny and ask rules survive additional approval paths, including managed-plugin approvals and sandbox auto-allow, according to the release thread.
- Teammates gain
agent.spawn; ClaudeCodeLog also reports consistent agent IDs across plugin hooks and explicit idle/waiting states. - Plugin failures get tighter containment: the changelog describes component-level faults, replacement rows and fixes for unexpectedly terminated sessions.
An environment prefix as ordinary as TZ="$HOME" could make sandbox auto-allow miss a Bash deny or ask rule. A user-installed plugin could also rewrite an organization's MCP sign-in tool descriptions.
Read denies and symlinks
Anthropic published 2.1.289 on October 3 at 23:07 UTC, after ClaudeCodeLog previewed the release. Its file-access fix covers Read deny rules that were not applying to:
@-mentioned files.- Files changed in the IDE through a symlink.
- Files selected in the IDE through a symlink.
The permissions reference gives Read(./.env) as an example of a file-scoped rule. It also specifies that Claude Code enforces permissions in the runtime; instructions in a prompt or CLAUDE.md do not change what the runtime allows.
Bash approval precedence
Bash deny and ask rules now survive three approval paths described in the release thread:
- Managed machines: A rule on a nested part of a compound shell command retains precedence over a user-installed mod's approval.
- Expanded environment prefixes: Sandbox auto-allow no longer misses a restricted command behind an assignment such as
TZ="$HOME" rm -rf build. - Bare assignments: A variable assignment preceding a command no longer causes sandbox auto-allow to skip a matching deny or ask rule.
The documented rule order is deny, then ask, then allow, regardless of rule specificity. For compound shell commands, each subcommand must match independently.
Sandbox auto-allow approves commands that can run inside the sandbox without prompting. Both sandbox modes enforce the same filesystem and network restrictions; their difference is the approval flow.
MCP sign-in descriptions
User-installed plugins can no longer rewrite the descriptions of an organization-managed MCP server's sign-in tools, according to ClaudeCodeLog's changelog. The repaired boundary concerns the sign-in tools' descriptive text.
Teammate spawning
Claude Code extends the teammate API with three changes in ClaudeCodeLog's announcement and thread:
agent.spawnis available to teammates for spawning shared agents.- One agent ID is used across plugin hook events.
$.agent.list()exposes idle and waiting states.
Plugin loading and fault isolation
A failed plugin Client now fails on its own and raises ui.fault, according to the release thread. Previously, its rendering failure could take down everything the mod drew around it.
Loading and validation
plugin list,plugin evalandplugin updatestop showing stale copies of plugins installed from local-folder marketplaces.- Hot reload works for a symlinked
--plugin-dir. - Installed mods load in the first session after an upgrade.
claude plugin validatehandles folders that also contain a marketplace manifest and fixes validation failures involving an Anthropic marketplace's own plugin.
Session and rendering failures
- Asynchronous exceptions in plugin on-screen handlers no longer terminate supervised or background sessions.
- When a value from
ui.rendermakes a row throw during drawing, the engine draws its own row instead of ending the session with an unrecoverable interface error. - A
Clientregion can recover after a terminal drawing exception rather than remaining failed for the session. - Short code blocks with many unclosed
<script>tags no longer freeze the terminal or freeze/crash published-artifact browser tabs. Deeply nested${substitutions also receive a terminal-freeze fix.
Large files also open faster in plugin code panes because the highlighted view is laid out once at its final width, as the changelog explains.
VS Code sign-outs
The VS Code extension reverts a 2.1.288 change to claude auth status that may have increased sign-outs, according to the release thread. Anthropic's wording describes a possible regression, rather than attributing every sign-out to that change.
Prompt inventory and CLI strings
ClaudeCodeLog's bundle comparison reports additional changes outside the user-facing changelog:
- Extracted prompts: One additional prompt file (+6.7%) and 5,031 additional counted tokens (+17.8%).
- Token mix: System prompts rise from 46.3% to 54.4% of the inventory; tool prompts fall from 53.7% to 45.6%.
- Tracked CLI surface: The model strings
claude-code-userandclaude-lsremote-disappear.
The version-pinned prompt table lists four User Memory Project One variants separately. The fourth variant debuted in 2.1.289 and is itself counted at 5,031 tokens; these statistics describe the tracker's extracted prompt inventory.