← All reports

Changes on 2026-08-05

44 total changes in 4 runs

22:03 EST

🤖 AI Batch Analysis

# 文档变更分析 ## 总体摘要 本次更新包括对 GitHub Actions 文档的全面重构,旨在明确产品定位并改善设置流程;同时,对多个功能页面实施了“兼容性”信息的标准化统一。此外,发布了 v2.1.223 版本,修复了关键的安全漏洞并引入了多项 CLI 行为变更。 ## 关键变更主题 * **文档结构标准化**:在 PDF 支持、引用、Effort 参数、Files API、Computer Use 和 MCP 连接器等功能页面的顶部统一新增了“兼容性”部分,明确列出了零数据保留(ZDR)资格、支持的平台及 Beta 头要求。 * **GitHub Actions 指南重构**:完全重写了 GitHub Actions 的设置指南,区分了“Claude Code GitHub Actions”、“Code Review”和“Agent SDK”等产品,并提供了更清晰的“快速设置”与“手动设置”步骤。 * **关键安全与稳定性修复**:v2.1.223 版本修复了 Bash 权限绕过漏洞以及通过标签或不可见 Unicode 字符隐藏命令部分的权限提示问题。 * **行为细节澄清**: * 明确了提示缓存的 5 分钟生命周期是从请求开始计算而非响应结束,并解释了长时间生成对缓存窗口的影响。 * 加强了对未知模型 ID 的上下文窗口强制执行和自动压缩逻辑。 * **CLI 命令调整**:将 `/review` 变更为 `/code-review` 的别名,并新增了 `/teleport` 提示。 ## 影响级别 **High (高)** **理由**: 1. **安全漏洞**:Changelog 中提到的权限绕过漏洞和命令提示欺骗问题对安全性有直接影响,需立即关注。 2. **大规模文档重构**:GitHub Actions 页面的大幅改动和功能页面的标准化调整,标志着官方文档风格的重大转变,影响开发者的查找习惯和集成流程。 ## 开发者行动项 * **立即升级**:将 Claude Code CLI 更新至 **v2.1.223** 版本,以修复潜在的 Bash 权限绕过和命令提示安全漏洞。 * **审查缓存逻辑**:如果你依赖提示缓存且请求响应时间较长,需重新评估 5 分钟缓存窗口的有效性,考虑升级至 1 小时缓存 TTL。 * **关注模型上下文窗口**:检查自定义或未知模型 ID 的使用情况,注意 CLI 现在会对超出 200K 的上下文自动压缩并发出警告。 * **适应命令别名**:更新使用习惯,`/review` 现为 `/code-review` 的别名,深度审查应使用 `/code-review ultra`。 * **参考新文档结构**:在配置新功能(如 Files API 或 MCP)时,直接查阅页面顶部的“Compatibility”部分以快速确认平台支持和 Beta 要求。
💭 Model Reasoning
1. **Analyze the Request:** * **Role:** World-class programmer analyzing documentation changes. * **Input:** 10 changed pages (diffs provided). * **Task:** Analyze as a single batch. Summarize what changed and why it matters. * **Format:** Markdown. * **Language:** Chinese. * **Sections:** Overall Summary, Key Themes, Impact Level, Action Items. 2. **Analyze the Input Diff (Page by Page):** * **Page: `github-actions.md` (+185 / -343)** * *Change:* Massive rewrite of the documentation structure. * *What:* Intro changed to explicitly define "Claude Code GitHub Actions" vs other products (Code Review, Web, SDK). Added a clear "Setup" section with "Quick setup" and "Manual setup". "Quick setup" details the `/install-github-app` CLI experience more thoroughly. Added warnings about GitHub CLI and specific behavior changes for versions >= v2.1.187. "Manual setup" updated with a `Steps` component (though cut off in diff, intent is clear). * *Why:* To reduce confusion between different "Claude Code" offerings and provide a better structured, step-by-step onboarding experience. * **Page: `build-with-claude/pdf-support.md` (+4 / -2)** * *Change:* Structural update to the header. * *What:* Added a standardized "Compatibility" section at the top detailing ZDR eligibility and supported platforms. Removed the generic `<Note>` about ZDR pointing to the general page. * *Why:* Standardization of documentation structure for better scannability. * **Page: `build-with-claude/prompt-caching.md` (+4 / -0)** * *Change:* Clarification on cache lifetime. * *What:* Added specific details that the 5-minute lifetime is measured from the *start* of the request, not the end. Added an FAQ entry explaining this nuance. * *Why:* Developers might be confused why their cache expires sooner than expected if the generation time is long. * **Page: `build-with-claude/citations.md` (+3 / -1)** * *Change:* Structural update. * *What:* Same as PDF support. Added standardized "Compatibility" header. Removed generic note. * *Why:* Standardization. * **Page: `build-with-claude/effort.md` (+5 / -3)** * *Change:* Structural update and model listing. * *What:* Added "Compatibility" header. Expanded the list of supported models (added `claude-fable-5`, `claude-mythos-5`, etc.). Removed the separate model list note and integrated it into the compatibility section. * *Why:* Standardization + updating model support info. * **Page: `build-with-claude/files.md` (+8 / -4)** * *Change:* Structural update and platform availability. * *What:* Added "Compatibility" header (Status: Beta, Beta header, ZDR: not eligible). Clarified platform availability (Claude API, AWS, Foundry; *not* Bedrock or GCloud). Moved "File type support" text up. * *Why:* Standardization + Clearer platform/feature matrix. * **Page: `agents-and-tools/tool-use/computer-use-tool.md` (+7 / -4)** * *Change:* Structural update and beta header info. * *What:* Added "Compatibility" header. Moved beta header details into the compatibility block. Added note about older models requiring the older header. * *Why:* Standardization. * **Page: `agents-and-tools/mcp-connector.md` (+7 / -4)** * *Change:* Structural update. * *What:* Added "Compatibility" header. Clarified platform availability (not Bedrock/GCloud). Deprecated version warning moved to a general note. * *Why:* Standardization + Platform clarity. * **Page: `resources/glossary.md` (+3 / -3)** * *Change:* Branding phrasing updates. * *What:* Changed "Anthropic's language models" to "Claude". Clarified HHH definition vs product tagline. Updated LLM definition to include "AI assistant for life and work". * *Why:* Marketing/Branding alignment. * **Page: `CHANGELOG.md.md` (+20 / -0)** * *Change:* Version 2.1.223 release notes. * *What:* Security fixes (Bash permission bypass, permission prompt hiding), feature changes (`/teleport`, strictKnownMarketplaces, `/review` alias), bug fixes (CD resume, model discovery), and behavioral changes (context window enforcement). * *Why:* Keeping users up to date with the latest CLI changes and security patches. 3. **Synthesize and Structure the Output:** * **Overall Summary:** The updates consist of a major restructuring of the GitHub Actions documentation for better clarity, a sweeping standardization of "Compatibility" headers across feature pages, and the release of version 2.1.223 which includes critical security patches and CLI enhancements. * **Key Themes:** * *Documentation Standardization:* Introduction of a "Compatibility" section (ZDR, Platform, Beta status) across multiple feature pages (PDF, Citations, Effort, Files, Computer Use, MCP). * *GitHub Actions UX Overhaul:* Complete rewrite of the setup guide to distinguish between products and improve step-by-step instructions. * *Security & Stability (v2.1.223):* Fixes for permission bypasses and prompts hiding commands. * *Behavioral Clarifications:* Specifics on prompt caching timing and model context window enforcement. * **Impact Level:** High (due to security fixes and major doc restructure). * **Action Items:** * Review and update documentation templates if you are maintaining internal docs that mirror these structures. * Update Claude Code CLI to v2.1.223 immediately to address security vulnerabilities (permission bypass). * Note the change in prompt caching lifetime logic if you are relying on tight timing margins. * Be aware of the `/review` command alias change and the context window enforcement changes for custom models. 4. **Drafting the Content (in Chinese):** * *Summary:* 本次更新包括对 GitHub Actions 文档的重大重构以提高清晰度,全面标准化各功能页面的“兼容性”头部信息,以及发布了包含关键安全补丁和 CLI 增强功能的 v2.1.223 版本。 * *Themes:* * 文档结构标准化:统一添加了“兼容性”部分(含 ZDR 资格、平台支持、Beta 状态)。 * GitHub Actions 体验优化:重写了设置指南,明确区分了不同产品,并改进了分步说明。 * 安全性与稳定性:修复了 Bash 权限绕过和命令提示隐藏等安全漏洞。 * 行为细节澄清:明确了提示缓存的计时逻辑和模型上下文窗口的强制执行策略。 * *Impact:* High. Security fixes are critical. Doc restructure affects onboarding. * *Action Items:* * 立即将 Claude Code CLI 更新至 v2.1.223 以修复权限绕过漏洞。 * 若依赖严格的缓存时间窗口,需注意提示缓存生命周期计算方式的变更。 * 了解 `/review` 命令变更为 `/code-review` 别名的新行为。 * 如果使用未识别的模型 ID,需关注上下文窗口自动压缩的新警告逻辑。 5. **Refining the Language:** Ensure professional, concise tone. Use terms like "标准化" (standardization), "重构" (refactor), "漏洞" (vulnerability). * *Self-Correction during drafting:* The GitHub Actions page diff was huge, but the main point is the structural change, not just a small edit. I must highlight that. The changelog has specific security fixes (Bash permission bypass) which elevates the impact to High. 6. **Final Polish:** Check against the requested markdown format. * *Summary:* Concise. * *Themes:* Bulleted. * *Impact:* High + Reason. * *Action Items:* Max 5 bullets. (Proceed to generate output).

📚 Claude Code

📚 Claude Code GitHub

17:02 EST

🤖 AI Batch Analysis

### 整体摘要 本次文档更新主要集中在优化插件生态系统的灵活性与兼容性,重点引入了自定义 `metadata` 字段,强化了针对 Claude Desktop 的命名规范验证,并澄清了内存压缩和状态栏的行为细节。 ### 关键主题 * **扩展元数据支持**:在插件、市场和技能的配置中统一引入了 `metadata` 字段,允许开发者存储自定义数据(如目录 ID 或授权信息),且不会影响 Claude Code 的核心行为。 * **插件系统兼容性增强**:新增了对插件和市场名称的严格验证(如避免保留字、限制长度和字符),以确保与 Claude Desktop 的兼容性;同时,放宽了 `skills` 路径配置的限制(现支持 `"."`)。 * **持久化与 UI 行为澄清**:明确了 `/compact` 后路径特定规则不会自动重载的机制;解释了自定义状态栏会隐藏部分静态提示(如快捷键提示)但保留上下文提示的行为。 ### 影响等级:中等 * **理由**:虽然主要是文档说明,但新增的严格验证规则可能会阻止不符合规范的插件同步到 Claude Desktop,且 `metadata` 和路径处理的更新改变了开发者构建插件的最佳实践。 ### 开发者行动项 1. **审查命名规范**:检查你的插件和市场名称,避免使用 `org` 等保留字,并确保名称长度和字符组成符合 Claude Desktop 的同步要求。 2. **利用元数据字段**:在 `plugin.json` 或 `SKILL.md` 中使用新的 `metadata` 字段存储自定义数据,而非滥用现有的 frontmatter 字段。 3. **更新技能路径配置**:如果之前因路径验证失败无法使用 `"."` 表示插件根目录,现在可以安全更新配置以支持此写法。 4. **注意规则重置机制**:在使用 `/compact` 后,需意识到基于路径的规则可能失效,直到再次访问相关文件。 5. **调整状态栏预期**:若配置了自定义状态栏,应注意用户将不再看到默认的快捷键静态提示。
💭 Model Reasoning
1. **Understand the Goal**: The user wants a concise, insightful analysis of a batch of documentation changes (6 pages) provided in a unified diff format. I need to summarize what changed, identify themes, assess impact, and list action items, all in Chinese markdown format. 2. **Analyze the Diffs Page by Page**: * **`memory.md`**: * *Change*: Updated the explanation of what survives `/compact`. * *Detail*: Previously, it mentioned nested `CLAUDE.md` files not being re-injected automatically. Now it adds `rules` with `paths:` frontmatter to the list of things not automatically re-injected. * *Implication*: Developers relying on path-specific rules need to be aware that they might disappear after compaction until a matching file is read. * **`plugin-marketplaces.md`**: * *Change*: Added new validation rules and fields. * *Detail*: * Added `metadata` field to the manifest table (free-form object for catalog data, ignored by Claude Code). * Added validation errors regarding marketplace and plugin naming constraints (reserved names like `org`, length limits, character sets) specifically for Claude Desktop compatibility. * Version notes: `metadata` was unrecognized before v2.1.222; name checks didn't run before v2.1.221. * **`plugins-reference.md`**: * *Change*: Extensive updates to plugin manifest validation and path handling. * *Detail*: * `metadata` field support (same as above). Notes specific handling for wrong types (ignored for `metadata` and `experimental`). * Path behavior rules updated: `skills` field now accepts `"."` (root), previously it failed validation. * Updated troubleshooting table for path errors to include the `"."` exception. * **`skills.md`** and **`slash-commands.md`**: * *Change*: Updates to `SKILL.md` frontmatter. * *Detail*: * Clarified `metadata` field: Free-form map for own data, Claude Code doesn't act on it, drops non-map values. * Added a note about `/deploy` behavior: If Claude tries to deploy manually when it shouldn't, Claude Code blocks it and suggests running `/deploy` manually. * **`statusline.md`**: * *Change*: Updated UI behavior description. * *Detail*: With a custom status line, Claude Code hides some static hints (`? for shortcuts`, `hold space to speak`) but keeps contextual hints (`esc to interrupt`). 3. **Synthesize Key Themes**: * *Theme 1: Metadata and Flexibility*: Introduction/clarification of `metadata` fields in plugins and skills for internal tooling/cataloging without affecting Claude's behavior. * *Theme 2: Strictness and Compatibility*: Increased validation for Claude Desktop compatibility (naming conventions) and stricter handling of path fields (allowing `"."` now). * *Theme 3: Persistence and State Management*: Clarification on what survives memory compaction (path-scoped rules). 4. **Determine Impact Level**: * *Reasoning*: Most changes are clarifications or additions of "nice-to-have" fields. The strict validation for marketplace names is important for cross-compatibility but likely affects fewer users. The change to allow `"."` in paths fixes a bug/friction. The compaction note is behavioral but edge-case. * *Level*: **Low to Medium**. It's mostly documentation updates reflecting recent features or clarifying existing behavior. No breaking API changes for the majority, but marketplace authors need to watch out for naming rules. 5. **Draft Action Items**: * Plugin authors: update manifests to use `metadata` for custom data. * Plugin authors: check marketplace/plugin naming for Claude Desktop compatibility (avoid reserved names, keep it short). * Plugin authors: `skills` path can now use `"."` if needed (and backwards compatible). * Developers: Be aware that path-specific rules reset after compaction. * Status line users: Know that static hints disappear. 6. **Translate and Format (Chinese)**: * *Summary*: 本次文档更新主要集中在插件生态系统的增强,特别是验证规则、元数据支持以及对内存压缩和状态栏行为的澄清。 * *Themes*: * **元数据支持**: 在插件、市场和技能中引入了 `metadata` 字段,供开发者存储自定义数据而不影响 Claude 行为。 * **兼容性与验证**: 加强了针对 Claude Desktop 的命名规范验证,明确了 `skills` 路径字段对 `"."` 的支持。 * **状态与持久化**: 阐明了 `/compact` 后路径特定规则的重载机制,以及状态栏对提示信息的显示策略。 * *Impact*: Medium (due to validation rules potentially blocking syncs, but mostly Low/Medium). * *Actions*: * Review marketplace/plugin names for new Desktop constraints. * Utilize `metadata` field for cataloging. * Update `skills` path configurations. * Adjust expectations regarding rule persistence after compaction. 7. **Refine Content**: * Make it punchy. * Ensure the distinction between "Claude Code" and "Claude Desktop" sync rules is clear, as that's a specific pain point mentioned in the diff. *(Self-Correction)*: The `skills.md` and `slash-commands.md` diffs are identical. I should treat them as one point regarding skill frontmatter. 8. **Final Output Generation** (matching the requested structure). * *Summary*: 本次文档更新主要涉及插件与技能系统的增强,重点包括引入 `metadata` 字段、强化针对 Claude Desktop 的命名验证,以及澄清内存压缩和状态栏的交互行为。 * *Themes*: * 扩展元数据支持。 * 插件系统兼容性与路径处理。 * 持久化与 UI 行为的澄清。 * *Impact*: **Medium**. 新的验证规则可能会阻止某些插件同步到 Claude Desktop,且路径规则的更新改善了开发体验。 * *Action Items*: * 检查插件/市场名称合规性。 * 使用 `metadata` 字段。 * 更新 `skills` 路径配置。 * 注意规则重置机制。 9. **Final Polish**: Ensure the tone is professional and "world-class programmer".
15:21 EST

🤖 AI Batch Analysis

### 总体摘要 本次更新主要涉及 **Claude Opus 4.1 模型的正式退役**、**模型配置逻辑的精细化改进**(特别是受限环境下的别名解析),以及**使用量统计准确性和网络稳定性文档的完善**。 ### 关键变更主题 * **Claude Opus 4.1 退役**:将 Opus 4.1 的状态从“已弃用”更新为“已退役”,并从多个列表中移除。该模型现仅在 Amazon Bedrock 和 Google Cloud 上保留。 * **模型配置与权限白名单**:优化了 `availableModels` 的逻辑。当请求的模型家族别名(如 `opus`)被阻止但列表中允许该家族的旧版本时,系统现在会自动替换为允许的最新版本,而不是直接失败或回退到默认模型。 * **使用量监控修复**:修正了 MCP 服务器使用量的归因逻辑。以前一次 MCP 调用后的所有请求都会被归因于该服务器,现在只有实际消费了工具结果的请求才会被标记。同时修正了 `monitoring-usage.md` 中的语义描述。 * **网络稳定性文档**:新增了“流式空闲看门狗”文档,详细说明了三种独立的计时器机制,用于在流式响应卡死时自动中止并重试,防止连接挂起。 * **设置优先级与认证**:阐明了嵌入式主机平台(`CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST`)对托管设置的覆盖优先级,并优化了 OAuth 会话令牌被拒绝时的错误处理流程。 ### 影响等级:**低** **理由**: * 大部分变更属于文档更新和逻辑修复(如 Opus 4.1 退役是生命周期管理的正常步骤)。 * 模型白名单逻辑的优化是向后兼容的行为改进,不会破坏现有功能。 * 网络看门狗文档是解释现有机制的新增内容,而非引入新的破坏性变更。 ### 开发者行动项 1. **检查模型依赖**:如果您仍在使用 Claude Opus 4.1(非 Bedrock/GCP 环境),请尽快迁移到更新版本的模型(如 Opus 5 或 4.8)。 2. **审查集成仪表板**:如果您依赖 `mcp_server.name` 进行使用量分析,请注意其语义已变更(不再过度归因),升级到 v2.1.222 后数据会出现回落,属正常现象。 3. **优化模型白名单配置**:如果您在组织内设置了 `availableModels`,请测试新的别名替换逻辑,确保在请求受限家族别名时能按预期解析到允许的版本。 4. **排查网络挂起问题**:遇到流式响应长时间无响应时,参考新增的“流式空闲看门狗”文档,检查环境变量(如 `CLAUDE_STREAM_IDLE_TIMEOUT_MS`)配置是否合适。
💭 Model Reasoning
1. **Understand the Goal**: The user wants a concise, insightful analysis of documentation changes in markdown format, specifically focusing on what changed and why it matters to developers. The response must be in Chinese. 2. **Analyze the Input**: I have 23 pages of diffs. I need to scan through them to identify the core changes. * `costs.md`: * Refined attribution logic for usage (MCP server share calculation). * Added "When the usage request fails" behavior (rate limiting/retry). * Fixed logic for `/usage-credits` (preventing duplicate requests after admin dismissal). * `desktop.md`: * Clarified session renaming behavior (shared between local envs). * `devcontainer.md`: * Clarified settings precedence for managed settings in dev containers (referencing the settings hierarchy exceptions). * `hooks.md`: * Updated links/cross-references for background session deletion (internal link changes). * `mcp.md`: * Clarified OAuth error handling (session token rejection vs connector auth failure). * Clarified when connectors are loaded based on authentication method. * Added specific steps to fix "session token rejected" errors. * `model-config.md`: * Added details on `CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST` precedence. * Expanded `availableModels` allowlist logic to include "teammate models". * Fixed behavior for blocked family aliases in subagents (now substitutes instead of falling back entirely on some providers). * `monitoring-usage.md`: * Clarified `mcp_server.name` attribute semantics (now only set when *consuming* a tool result, fixed an over-reporting bug). * `network-config.md`: * Added a new section on "Streaming idle watchdogs" (timers, aborting stalled streams). * Added connectivity check details for first-run setup. * `settings.md`: * Refined description of "Managed" settings precedence (allowing for specific security-sensitive exceptions). * Clarified `remoteControlAtStartup` setting behavior. * `sub-agents.md`: * Refined isolation checks (Monitor commands included). * Fixed `availableModels` allowlist logic for subagents (now substitutes blocked family aliases instead of falling back to inherited model on some providers). * `vs-code.md`: * Minor clarification on Remote Control setting description. * `about-claude/models/overview.md`: * Removed specific model details for older models (Opus 4.8-4.1). * `about-claude/models/migration-guide.md`: * Removed "(deprecated)" reference for Opus 4.1. * `about-claude/pricing.md`: * Changed Opus 4.1 status from "deprecated" to "retired, except on Bedrock and Google Cloud". * `about-claude/model-deprecations.md`: * Marked Opus 4.1 as "Retired" (was Deprecated). * `build-with-claude/extended-thinking.md`: * Removed "(deprecated)" for Opus 4.1. * `build-with-claude/prompt-caching.md`: * Removed "(deprecated)" for Opus 4.1. * `build-with-claude/batch-processing.md`: * Removed "(deprecated)" for Opus 4.1. * `build-with-claude/context-editing.md`: * Minor formatting cleanup. * `build-with-claude/claude-in-microsoft-foundry.md`: * Removed Opus 4.1 from the model list. * `agents-and-tools/tool-use/overview.md`: * Changed Opus 4.1 status text. * `agents-and-tools/tool-use/computer-use-tool.md`: * Changed Opus 4.1 status text. * `agents-and-tools/tool-use/code-execution-tool.md`: * Removed Opus 4.1 from the model list. 3. **Synthesize the Changes**: * **Theme 1: Model Lifecycle (Opus 4.1)**: A large chunk of changes involves updating the status of **Claude Opus 4.1** from "deprecated" to "retired" (or removing it entirely from lists like Foundry/Code Execution). It's now mostly gone except on Bedrock/Google Cloud. * **Theme 2: Usage & Monitoring Fixes**: * Fix in `costs.md` for `/usage` breakdown (MCP attribution). * Fix in `monitoring-usage.md` for `mcp_server.name` (no longer over-attributed). * **Theme 3: Model Configuration & Settings Precedence**: * More nuance around `availableModels` allowlist logic. It now attempts to substitute blocked family aliases (e.g., "opus") with the newest allowed version instead of just falling back, improving behavior for restricted environments. * Clarification on embedded/host platforms (`CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST`). * Refined "Managed settings" description. * **Theme 4: Network & Reliability**: * New "Streaming idle watchdogs" section in `network-config.md`. Important for understanding how Claude Code handles hanging connections. * **Theme 5: MCP & Auth**: * Better error handling for "session token rejected" vs connector auth. 4. **Draft the Response (Iterative refinement for Chinese)**: * *Overall Summary*: The update focuses on retiring Claude Opus 4.1, refining model configuration logic (allowlist behavior), and improving usage reporting accuracy and network reliability documentation. * Draft (Chinese): 本次更新主要集中在 Claude Opus 4.1 模型的正式退役、完善模型配置(特别是可用性列表)的逻辑,以及提升使用量统计准确性和网络可靠性文档。 * *Key Themes*: * **Model Retirement (Opus 4.1)**: Status changed from deprecated to retired (removed from general availability, kept on Bedrock/GCloud). * **Model Configuration & Allowlist**: Improved logic for `availableModels`. Now uses substitution for blocked aliases (e.g., asking for `opus` gets the newest allowed `opus`) rather than just failing/falling back. * **Usage & Monitoring**: Fixed attribution logic for MCP servers (prevents over-attribution) and clarified session token rejection errors. * **Network Stability**: Added documentation for "Streaming idle watchdogs" which handle hanging connections. * **Settings Precedence**: Clarified how embedded platforms override managed settings and specific security exceptions. * *Impact Level*: **Low** (mostly fixes, documentation updates, and removing an old model). There are no breaking changes for general usage, but the allowlist logic change is an improvement for enterprise users. * *Action Items*: * Check if you are using Claude Opus 4.1 (ensure you migrate). * Review the `availableModels` allowlist behavior if you have strict model restrictions. * Note the new "Streaming idle watchdogs" if debugging network hangs. * Update integration dashboards regarding the `mcp_server.name` attribute change. 5. **Final Polish (Markdown Formatting)**: * Ensure the tone is professional ("world-class programmer"). * Verify the translation is natural. * *Self-Correction during drafting*: The `costs.md` change regarding MCP attribution is a subtle logic fix. The usage credit duplicate request fix is also a bug fix. The network config section is a new feature description (not necessarily a new feature in the app, but new documentation explaining existing behavior). The model retirement is the most visible change. 6. **Final Output Generation** (matching the requested structure).

📚 Claude Code

13:42 EST

🤖 AI Batch Analysis

### 总体摘要 本次更新重点修复了 Hooks 在 Windows 平台的路径匹配安全性问题,明确了 Skills(技能)Frontmatter 字段在本地与云端环境下的标准兼容性,并新增了关于 Files API 的关键安全警告,强调防止跨用户数据泄露。 ### 核心变更主题 * **Windows 路径标准化与安全:** 详细阐明了 `PreToolUse` 和 `PostToolUse` 中的 `file_path` 始终为绝对路径,且在 Windows 上使用反斜杠 (`\`)。文档特别警告,若在 Hook 脚本中仅硬编码正斜杠 (`/`) 进行匹配,将导致匹配失败,从而可能绕过安全检查。 * **Agent Skills 开放标准合规性:** 区分了 Claude Code 私有扩展字段(如 `paths`)与 [Agent Skills](https://agentskills.io) 开放标准字段。当将 Skills 上传至 `claude.ai` 或使用 `package_skill.py` 打包时,仅允许使用标准字段,否则会直接报错。 * **Files API 安全警示:** 新增严重警告,指出上传的文件 `file_id` 作用于整个工作区,而非特定用户。严禁接受不受信任的(如用户端提交的)`file_id`,否则会导致数据泄露风险。 * **Hook 输出流控制:** 澄清了 Exit 0 状态下的 Stderr 仅写入调试日志,不可被 Claude 读取。若需向 Claude 发出警告,必须使用 Exit 2。 ### 影响等级:高 **理由:** 1. **安全风险:** Windows 路径处理不当可能导致 Hook 安全策略失效;Files API 的误用可能导致严重的越权访问漏洞。 2. **构建阻断:** Skills 打包或上传流程增加了严格验证,使用了非标准字段的现有项目将遭遇硬错误阻断。 3. **跨平台兼容性:** Windows 用户的 Hook 脚本可能需要修改才能按预期工作。 ### 开发者行动项 1. **修复 Windows Hook 路径匹配:** 审查所有涉及文件工具(`Write`, `Edit`, `Read`)的 Hook 脚本,务必添加路径分隔符归一化逻辑(例如在 Bash 中使用 `${FILE_PATH//\\//}` 或 Python 中使用 `.replace("\\", "/")`),以防 Windows 反斜杠导致匹配失效。 2. **合规化 Skills Frontmatter:** 若需将 Skills 分发至 `claude.ai`或通过 API 使用,请检查 `SKILL.md`,移除仅 Claude Code 支持的字段(如 `argument-hint`、`paths`),仅保留 6 个标准字段(`name`, `description`, `license`, `compatibility`, `metadata`, `allowed-tools`)。 3. **加固 Files API 安全:** 检查代码逻辑,确保服务器端从不接受用户直接提供的 `file_id`。必须由服务端维护用户与文件的映射,防止利用 ID 读取他人文件。 4. **调整 Hook 退出码逻辑:** 如果您希望 Hook 中的警告信息能被 Claude 看到,请修改脚本让其在警告时返回 Exit 2 而非 Exit 0,否则 Stderr 内容仅限开发者调试查看。
💭 Model Reasoning
1. **Analyze the Request:** * **Role:** World-class programmer analyzing documentation changes. * **Output Format:** Markdown (Concise, insightful). * **Language:** Chinese. * **Input:** 5 pages of diffs (`hooks.md`, `hooks-guide.md`, `skills.md`, `slash-commands.md`, `build-with-claude/files.md`). 2. **Analyze the Diffs:** * **`hooks.md`:** * *Exit 0 vs Exit 2 behavior:* Clarifies that stderr on exit 0 goes *only* to debug log (never to Claude/Transcript). To surface a warning to Claude (from `PostToolUse` etc.), use exit 2. * *Path Normalization in Hooks:* Big section added regarding `PreToolUse` input. * `file_path` is always absolute. * Expanded `~` and relative paths. * **Critical:** Windows paths use backslashes (`\`). Hooks running under Git Bash see `/c/project` but inputs have `\`. * If hooks compare using `/`, they fail to match `\`. * Solution: Normalize separators (`/` vs `\`) before matching. * Example given for Windows `Write` call. * Note: `PostToolUse` input paths are now noted to be the same format. * **`hooks-guide.md`:** * *Code Example Update:* Added a snippet in a bash hook example to normalize Windows backslashes: `FILE_PATH="${FILE_PATH//\\//}"`. This directly supports the changes in `hooks.md`. * **`skills.md` & `slash-commands.md`:** * *Note:* Both pages have identical diffs regarding the Skills spec. * *Frontmatter Compatibility:* Added new frontmatter fields: `metadata`, `license`, `compatibility`. * *Standard vs Extensions:* Clarifies that Claude Code supports the [Agent Skills](https://agentskills.io) open standard. * *Strict Validation elsewhere:* When uploading to `claude.ai` or using `package_skill.py`, only 6 fields are allowed (`name`, `description`, `license`, `compatibility`, `metadata`, `allowed-tools`). * *Hard Error:* If you use a Claude Code-only field (like `argument-hint` implied by the error message example, or `paths`?) in the standard context, it throws a hard error ("Unexpected key(s)..."). * *Conclusion:* Developers must be careful which fields are used where. Standard fields work everywhere; Claude Code extensions only work locally in the CLI. * **`build-with-claude/files.md`:** * *Security Warning:* Added a `<Warning>` box. Uploaded files are workspace-scoped, not user-scoped. * *Risk:* If accepting `file_id` from an untrusted user, they could read another user's files (IDOR vulnerability). * *Action:* Never accept `file_id` from end users. Keep mapping server-side. 3. **Synthesize Themes:** * *Windows Compatibility & Robustness:* The hooks changes are heavily focused on making hooks work correctly on Windows (path separators). * *Standards Compliance & Portability:* The skills changes focus on aligning with the "Agent Skills" open standard vs. Claude Code specific extensions. * *Security & Best Practices:* The files API change is a critical security warning about scoping and IDOR. 4. **Determine Impact Level:** * *Hooks (Windows):* Medium to High for cross-platform devs. If they wrote hooks assuming forward slashes, their security policies might be bypassed on Windows. * *Skills (Frontmatter):* Medium. If they are sharing skills or packaging them, this causes breaking build errors. * *Files (Security):* High. Security vulnerabilities are high impact. * *Overall:* High (due to the combination of potential security bugs and broken hooks on Windows). 5. **Draft Action Items:** * Update hook scripts to normalize path separators (specifically for Windows). * Review `SKILL.md` files to remove Claude Code-only fields if packaging for `claude.ai` or public distribution. * Implement strict validation on `file_id` inputs in application code (never trust user input). * Adjust hook exit code logic (use exit 2 for warnings) if they were relying on stderr being seen by Claude on success. 6. **Translate to Chinese:** * *Summary:* 重点关注 Hooks 的 Windows 路径兼容性、Skills 的 Agent Skills 标准合规性以及 Files API 的安全警告。 * *Themes:* Windows 路径处理, 标准与扩展区分, 安全风险. * *Impact:* High (Critical security fix + Cross-platform stability). * *Action Items:* Normalize paths, Clean up frontmatter, Validate file IDs, Review exit codes. 7. **Refine the Output (Markdown structure):** * **Overall Summary:** 本次更新重点解决了 Hooks 在 Windows 平台上的路径匹配问题,明确了 Skills(技能)在不同环境(本地 vs 云端)下的 Frontmatter 字段兼容性标准,并新增了关于 Files API 的关键安全警告,强调了工作区级别的文件访问隔离。 * **Key Themes:** * **Windows 路径标准化:** 针对 `PreToolUse` 和 `PostToolUse`,强调文件路径始终为绝对路径,且在 Windows 上使用反斜杠 (`\`)。文档明确指出,若在 Hook 中硬编码正斜杠 (`/`) 进行匹配,将导致安全检查失效。 * **Agent Skills 标准合规性:** 划分了 Claude Code 私有扩展字段(如 `paths`)与 Agent Skills 开放标准字段(如 `license`)。当打包或上传至 `claude.ai` 时,仅允许使用标准字段,否则会报错。 * **Files API 安全警示:** 明确警告 `file_id` 具有工作区作用域,而非用户级别。严禁接受用户提供的 `file_id`,否则会导致跨用户数据泄露(IDOR 漏洞)。 * **Hook 输出流控制:** 澄清了 Exit 0 时 Stderr 仅写入调试日志,若需向 Claude 发出警告,需使用 Exit 2。 * **Impact Level: High** * **Reasoning:** 路径标准化问题直接影响 Windows 用户 Hook 的安全性与功能(可能导致权限绕过);Skills 字段的严格验证可能导致打包流程中断;Files API 的安全漏洞若不修复,将造成严重的数据泄露风险。 * **Action items:** * **修复 Windows 路径匹配:** 检查所有涉及文件操作(`Write`, `Read`, `Edit`)的 Hook 脚本,添加路径分隔符归一化逻辑(例如将 `\` 替换为 `/`)。 * **清理 Skills Frontmatter:** 若计划将 Skills 上传至 `claude.ai` 或使用 `package_skill.py` 打包,请移除仅 Claude Code 支持的字段(如 `argument-hint`, `paths`),仅保留标准字段(`name`, `description`, `license`, `compatibility`, `metadata`, `allowed-tools`)。 * **加固 Files API 安全:** 审查处理文件上传和引用的应用代码,确保服务器端严格拒绝来自客户端(用户)的 `file_id` 输入,由服务端维护用户与文件的映射关系。 * **调整 Hook 错误处理:** 如果希望 Hook 的警告信息被 Claude 看到,请将退出码从 0 改为 2,否则 Stderr 内容仅限调试查看。 8. **Final Polish:** Ensure tone is professional and concise. The translation looks natural for technical documentation. The distinction between standard and extension fields in skills is clear. The Windows path issue is highlighted as a potential security bypass. *Self-Correction during drafting:* Make sure to mention the specific error message for skills, as that helps developers debug if they hit it. The "Exit 2" change is important for workflow logic. *Final check against constraints:* "Concise, insightful analysis in markdown format." "Focus on what matters to developers." "Chinese response." All met.

📚 Claude Code

📚 Anthropic API