# 文档变更分析
### 1. 总体概述
此次更新重点强化了企业级配置管控能力(特别是模型选择限制和凭证保护),优化了系统资源管理(如未使用插件检测和 MCP 超时机制),并引入了针对 **v2.1.187** 版本的多项交互体验改进。
### 2. 关键主题
* **企业级模型治理与配置传递**
* `availableModels` 设置的范围大幅扩展,现在不仅限制主会话模型,还严格限制 Subagents、Skills、Commands 和 Advisor 的模型选择。
* 明确了不同配置方式(服务器托管 vs MDM/文件)在不同运行环境(CLI、Desktop、Web、Cloud、SSH)下的覆盖范围和传递逻辑。
* 细化了别名行为:列出具体模型 ID 会从选择器中移除其裸别名(如仅列出 `claude-haiku-4-5` 会移除 `haiku`)。
* **安全性与沙箱增强**
* 新增 `sandbox.credentials` 配置项,允许显式禁止沙箱命令访问特定的凭证文件(如 `~/.aws/credentials`)和环境变量(如 `GITHUB_TOKEN`)。
* **资源管理与性能优化**
* 新增 MCP 工具调用的“空闲超时”机制(默认 5 分钟),针对无响应的远程服务器(HTTP/SSE/WS)自动中断调用,防止无限期挂起。
* 插件管理页面增加了“近期未使用”分组,帮助开发者清理闲置插件以减少启动开销。
* **v2.1.187 版本新特性**
* 交互模式新增 `Left`/`Right` 键用于在 `/btw` 的历史回答之间导航。
* `/install-github-app` 命令增加“暂且跳过”选项,允许仅安装 App 而不立即配置 Actions。
### 3. 影响等级
**Medium (中等)**
**理由:**
虽然此次更新主要是功能增强和文档澄清,但对企业用户和运维人员影响显著。`availableModels` 限制范围的扩大可能会破坏现有的自定义 Skills 或 Subagents 配置(如果它们使用了被限制的模型)。新的 MCP 空闲超时机制(5分钟)可能会导致现有的长时间运行工具调用意外失败。新引入的凭证保护功能则需要调整安全配置。
### 4. 开发者行动项
* **检查模型配置**:如果您设置了 `availableModels`,请确保列出了 Skills 和 Subagents 所需的特定版本前缀或完整 ID,避免因别名移除导致功能失效。
* **更新沙箱安全策略**:建议在项目或组织设置中利用新增的 `sandbox.credentials` 字段,显式屏蔽敏感文件和环境变量,而非仅依赖默认读取权限。
* **审查 MCP 工具超时**:如果您使用远程 MCP 服务器且工具调用时间超过 5 分钟,需调整 `CLAUDE_CODE_MCP_TOOL_IDLE_TIMEOUT` 环境变量以适应业务需求。
* **清理闲置插件**:利用插件列表中的“近期未使用”功能,识别并卸载不再使用的插件,以提升启动速度和上下文效率。
* **升级客户端**:升级至 Claude Code v2.1.187 或更高版本以启用新的快捷键导航和 GitHub App 安装控制流。
💭 Model Reasoning
1. **Analyze the Request:**
* **Role:** World-class programmer analyzing documentation changes.
* **Task:** Analyze 15 changed pages as a single batch.
* **Output:** Markdown format (Chinese language requested at the start: "请用中文回复").
* **Sections Required:**
1. Overall Summary (1-2 sentences).
2. Key Themes (bullets).
3. Impact Level (Low/Medium/High/Breaking) + Reasoning.
4. Action Items for Developers (bullets, max 5).
2. **Analyze the Diff Content (Page by Page):**
* **`amazon-bedrock.md`**:
* *Change:* Updated example for `availableModels`. Replaced `"haiku"` with `"claude-haiku-4-5"`. Clarified that listing a specific ID removes bare aliases.
* *Theme:* Model configuration/aliasing specificity.
* **`claude-code-on-the-web.md`**:
* *Change:* Updated table about cloud sessions. Added mention of "server-managed settings" arriving separately. Refined wording on availability.
* *Theme:* Cloud session behavior, managed settings.
* **`desktop.md`**:
* *Change:* Clarified "Managed settings". Refined descriptions for `managedMcpServers`. Explained where managed settings apply (Desktop vs CLI vs IDE).
* *Theme:* Managed settings, enterprise configuration.
* **`discover-plugins.md`**:
* *Change:* New section in "Installed" tab: "Not used recently". Logic: 2 weeks, 10 sessions. Added "Last used" line. Exceptions: Managed plugins, LSP servers, themes, etc.
* *Theme:* Plugin management, performance optimization (cleaning up unused plugins).
* **`github-actions.md`**:
* *Change:* Updated `/install-github-app` command description. Added "Skip for now" option in v2.1.187 to install just the App without workflows immediately.
* *Theme:* CI/CD setup, version-specific features (v2.1.187).
* **`interactive-mode.md`**:
* *Change:* New keybind: `Left` / `Right` to navigate between `/btw` answers. Version: 2.1.187+.
* *Theme:* UI interaction, version-specific features.
* **`mcp.md`**:
* *Change:* New behavior in v2.1.187: MCP tool calls abort after 5 minutes of no response/progress (idle timeout). Env var `CLAUDE_CODE_MCP_TOOL_IDLE_TIMEOUT` to control/disable. Stdio servers exempt.
* *Theme:* MCP timeout handling, performance/reliability.
* **`model-config.md`**:
* *Change:* *Major Update.* `availableModels` logic clarification. Now applies to skills, commands, advisor, background agents. Added "Surface coverage" table explaining where settings apply (CLI, IDE, Desktop, Web, Cloud, etc.). Clarified that listing full IDs removes bare aliases.
* *Theme:* Enterprise model governance, settings precedence, surface coverage.
* **`monitoring-usage.md`**:
* *Change:* Clarification on `attempt` attribute in `claude_code.api_error` event. It equals max_retries + 1 (e.g., 11 if max is 10).
* *Theme:* Monitoring/Observability accuracy.
* **`sandboxing.md`**:
* *Change:* New feature: `sandbox.credentials`. Protects files and environment variables. Explicit `mode: "deny"`. v2.1.187+.
* *Theme:* Security, sandboxing, credential protection.
* **`settings.md`**:
* *Change:* Updated "Available scopes" table with more detail on Managed settings (Server-managed, registry, etc.). Updated `availableModels` description to match `model-config.md` (skills, etc.).
* *Theme:* Settings structure, scope clarity.
* **`skills.md`** & **`slash-commands.md`**:
* *Change:* Updated documentation for frontmatter fields (likely wrapping/formatting changes based on the truncated output in the prompt, but looking closely at the provided snippets: The snippets are truncated in the prompt itself, showing the same table start. I'll assume consistency updates or formatting based on other changes).
* *Theme:* Documentation consistency.
* **`sub-agents.md`**:
* *Change:* Added note about `availableModels` allowlist checking for subagent model parameters. If excluded, falls back to inherited model.
* *Theme:* Model governance enforcement.
* **`CHANGELOG.md.md`**:
* *Change:* Added v2.1.190 (bug fixes). v2.1.187 mentioned in context of other changes.
* *Theme:* Version history.
3. **Synthesize Key Themes:**
* **Governance & Control:** Significant updates to `availableModels`, managed settings (`desktop.md`, `model-config.md`), and credential protection (`sandboxing.md`).
* **Version 2.1.187 Features:** Several new features explicitly tied to this version (Plugin cleanup, MCP idle timeout, `/btw` navigation, GitHub App skip option).
* **Enterprise/Cloud Context:** Clarification on how settings propagate to cloud sessions, web sessions, and desktop SSH environments.
* **Refinements:** Updates to API error logging, model aliasing behavior.
4. **Determine Impact Level:**
* *Reasoning:* The changes to `availableModels` are significant for enterprise admins configuring model access across all surfaces. The new `sandbox.credentials` feature impacts security compliance. Version 2.1.187 introduces noticeable UX/behavior changes (idle timeouts, cleanup UI). While not "Breaking" in the code-breaking sense, it changes operational behavior significantly for enterprises.
* *Level:* Medium to High (leaning Medium for general devs, High for Admins). Let's settle on **Medium** overall as it adds features and clarifies existing behavior without removing core functionality, but specific aspects are high impact.
5. **Draft Action Items for Developers:**
* Check for unused plugins using the new "Not used recently" feature.
* Review `availableModels` configuration if managing enterprise settings (mind the alias behavior).
* Update sandbox configs to use `sandbox.credentials` for better secret management.
* Monitor MCP tool calls for new 5-minute idle timeout if using long-running remote tools.
* Update local Claude Code to v2.1.187+ to access new keybinds and timeout controls.
6. **Translate to Chinese (Target Language):**
* *Summary:* 此次更新主要集中在增强企业级管理能力(如模型选择限制、凭证保护)、优化资源管理(插件清理、MCP 超时)以及改进 v2.1.187 版本的交互体验。
* *Themes:*
* 企业级管控与配置 (`availableModels` 扩展, Managed Settings 传输).
* 安全与沙箱增强 (新增 `sandbox.credentials`).
* 性能与维护 (插件未使用检测, MCP 空闲超时).
* 版本特性 (v2.1.187 功能: 导航键, GitHub App 设置).
* *Impact:* Medium (重要配置澄清和新安全功能,但主要是增强型更新).
* *Action Items:*
* Review `availableModels` settings (alias behavior change).
* Implement `sandbox.credentials` for secrets.
* Check MCP remote tool timeout limits.
* Update CLI for new shortcuts.
* Clean up plugins.
7. **Final Polish (Formatting):** Ensure Markdown structure is clean.
* *Self-Correction during translation:* Make sure to highlight that `availableModels` now affects Skills and Subagents, not just the main session. Make sure to mention the specific MCP idle timeout (5 mins) as it might break long-running tasks if not configured.
8. **Final Output Generation** (Proceed to generate Chinese response).