Skip to content
Agentsmedium signalverified

Claude Code 2.1.287 adds Mods and makes a 1M context window the default on cloud platforms

Anthropic released Claude Code 2.1.287 on October 1, 2026. The release adds Claude Mods, which let plugins modify deeper behavior, and a built-in mod in which a side agent flags things you might miss. Opus 4.7 and later and Fable now use a 1M context window by default on Bedrock, Vertex, Foundry, and the Claude apps gateway. Some MCP servers may stop connecting until you add one line to their configuration, and several shell writes that used to run now wait for approval.

By Redakcija WebAiRadarPublished 3 min readwritten by a model

Source

Release v2.1.287

Claude Code Releases (GitHub) · Original published October 1, 2026

Claude Code 2.1.287 is another long release, and most of its entries are small fixes. Five groups of changes can alter how an existing setup behaves: Mods, MCP sign-in prompts, a new telemetry field, a larger default context window on cloud platforms, and stricter approval for risky shell commands.

Mods let plugins go deeper

The release notes introduce Claude Mods in one line: plugins may now modify deeper behavior. They do not say what that behavior includes. The first built-in mod is called You should know. In it, a side agent watches the session and flags things you or Claude might miss. You turn it on with /plugin enable cc-plugin-you-should-know@builtin, and the notes limit it to first-party sessions with telemetry on.

MCP servers may need one more line

MCP servers on the 2025-11-25 protocol version can now send URL prompts, for example to sign you in. The notes warn that a server may no longer connect after this update. The fix they give is to add "bareElicitationCapability": true to that server's MCP config entry.

Two more MCP changes affect existing configurations. Setting alwaysLoad: false on a server now defers all of that server's tools behind tool search. Organization per-tool permission ceilings were silently dropped for an MCP tool named __proto__, and that is fixed.

The prompt gets a second copy in telemetry

The OpenTelemetry user_prompt event gains a field named prompt_text. It is a copy of prompt, added for backends that nest dotted keys. The notes tell you to drop or mask it wherever you drop or mask prompt. A related privacy fix concerns /feedback and /bug. The pre-filled GitHub issue no longer includes your recent error messages, and the confirmation screen now lists them as part of the report.

1M context becomes the default on cloud platforms

Opus 4.7 and later models and Fable now use a 1M context window by default on Bedrock, Vertex, Foundry, and the Claude apps gateway. The [1m] suffix on the model name is no longer needed. Setting CLAUDE_CODE_DISABLE_1M_CONTEXT=1 keeps the window at 200K. Two model fixes come with the change. Picking Fable in /model on a claude.ai login used to save the current version's id, and the saved default now follows the newest Fable. In /advisor, Sonnet 5.5 can now advise Opus 4.7 and 4.8.

Shell commands that now wait for a person

Several changes concern commands that write to places they should not reach without a person's approval.

  • The always-ask safeguard was lost for dangerous rm commands, such as one on / or the home directory, when the same command also redirected output to a ~ or wildcard path. That is fixed.
  • Shell writes through a symlink committed to the repository, onto a sensitive file or out of the working tree, now name where they land and wait for a person.
  • Whole-tool Bash allow rules and allowing hooks now prompt for shell writes to files that Claude Code's file tools refuse outright, such as the Anthropic profile store and the host credentials file. Before this release, such writes ran.
  • Sandboxed Bash commands on Linux inherited an open handle on the Claude Code executable. That is fixed.
  • On Windows, a startup warning now appears when denying the Bash tool also turns off the PowerShell tool, which leaves Claude with no shell tool.
„plugins may now modify deeper behavior“
Claude Code 2.1.287 release notes
BrandsClaude

Related

Customize Claude Code with mods in TypeScript | Claude by Anthropic
Agentsstrong signal

Claude Code mods are not sandboxed, and version 2.1.289 fixes a deny rule they could override

Anthropic introduced mods for Claude Code on October 1, 2026. They are TypeScript functions, shipped inside plugins, that can rewrite prompts, change tool calls, and redraw parts of the interface. The documentation says mods are not sandboxed and run with your permissions, which covers your files, environment variables, and API keys. On Team and Enterprise plans a built-in mod named sec-default loads first and restricts the mods that users install. Versions 2.1.288 and 2.1.289 fix several cases where permission rules did not hold.

Anthropicverified

Agentsmedium signal

GitHub Copilot retires four models and makes Balanced its default code review effort

GitHub deprecated four models across all Copilot experiences on October 2, 2026: Gemini 3.5 Flash, Gemini 3.6 Flash, Kimi K2.7 Code, and Claude Opus 4.7. On the same day it made Copilot code review available through the REST and GraphQL APIs. Balanced is now the default review effort level, a change that took effect on September 28, 2026. According to GitHub's documentation, a Balanced review consumes more AI credits than a Lite one.

GitHub Changelogverified

Apple's illustration for its notice on Full Disk Access: a white disk drive symbol on a gray rounded square, set on a light gray background.
Agentsmedium signal

Apple will add controls to Full Disk Access on macOS, citing risks from AI agents

Apple said on October 2, 2026, that it will add controls to Full Disk Access, the macOS permission that lets an app read nearly everything on a Mac. The company says some developers use the permission in ways that expose files, mail, messages, and browsing history without users fully understanding it. Apple expects the risk to grow as AI agents become more capable and autonomous. The post gives no date, no macOS version, and no description of the new controls.

Appleverified