← All reports

Changes on 2026-09-27

11 total changes in 2 runs

23:10 EST

🤖 AI Batch Analysis

# 文档变更分析 ## 总体摘要 此次更新主要集中在明确企业级身份与访问管理(IAM)策略的行为细节,特别是云服务商凭证与组织策略的交互逻辑;同时引入了用于审计配置文件的新工具 `/doctor prompt-audit`,并对文档中的术语引用进行了统一规范化。 ## 关键主题 * **IAM 策略收紧与澄清**:详细阐述了 `forceLoginOrgUUID` 和 Gateway 部署下的阻断行为。特别是明确了当机器上存在 API Key 时,云服务商会话(如 Amazon Bedrock)可能会被阻止启动,此前文档曾表述为“不阻止”。 * **新增配置审计工具**:引入了 `/doctor prompt-audit` 命令,用于自动检测项目中 `CLAUDE.md`、规则及技能文件的过时或冲突指令。 * **凭证上传与隐私**:移除了关于 linked worktree/submodule 可能上传敏感文件的例外说明,暗示了更统一的上传过滤机制。 * **术语规范化**:在 Hooks、Sub-agents 等多个页面的 "system reminder"(系统提醒)处增加了词汇表链接,提升了文档的可读性和一致性。 ## 影响等级 **中等** * **理由**:虽然大部分更改属于文档措辞优化和链接修复,但 `iam.md` 中的凭证阻断逻辑变更直接影响了开发者在使用云服务商(如 Bedrock)混合登录时的实际可用性。此外,新引入的审计工具对维护大型项目配置具有实际价值。 ## 开发者行动项 1. **检查混合登录环境**:如果你在设置了 `forceLoginOrgUUID` 的环境中同时使用 API Key 和云服务商凭证(如 AWS Bedrock),请务必清除本地的旧 API Key,否则云服务商会话可能会被意外阻止。 2. **试用配置审计**:在包含复杂 `CLAUDE.md` 或 `.claude/` 规则的项目中运行 `/doctor prompt-audit`,以清理过时指令或冲突。 3. **审查 Gateway 部署配置**:在 Gateway 部署场景下,确保 `forceLoginMethod` 和 `forceLoginOrgUUID` 未包含在 Gateway 提供的设置中,以符合新的管理要求。 4. **更新内置规则冲突处理**:如果你的自定义规则与 Git 提交或 PR 指令冲突,参考文档使用 `includeGitInstructions` 进行调整。
💭 Model Reasoning
1. **Analyze the Request:** * **Role:** World-class programmer analyzing documentation changes. * **Output Format:** Markdown, concise, insightful, focus on developer impact. * **Language:** Chinese (as requested in the system prompt: "请用中文回复"). * **Input:** A batch of 8 documentation page diffs. 2. **Analyze the Diffs:** * **`claude-code-on-the-web.md`**: * *Change:* Removed a sentence about linked worktrees/submodules uploading credential-like files. * *Impact:* Clarifies that credential filtering is more consistent/strict (or just simplifies the explanation). It seems to remove an exception where linked worktrees *would* upload sensitive files. * *Developer View:* Better privacy/security assurance for complex repo structures. * **`data-usage.md`**: * *Change:* Clarified the impact of disabling telemetry on "Remote Control". Changed from "depends on feature-flag evaluation" to "can make Remote Control unavailable". * *Impact:* More precise explanation of how `DISABLE_TELEMETRY` affects features. * *Developer View:* Better understanding of feature dependencies when configuring privacy settings. * **`hooks.md`** (2 changes): * *Change 1:* Added glossary link for "system reminder". * *Change 2:* Added glossary link for "system reminder". * *Impact:* Documentation hygiene. Links internal terms to the glossary for better discoverability. * *Developer View:* Easier to understand what "system reminder" means if unfamiliar. * **`hooks-guide.md`**: * *Change:* Added glossary link for "system reminder". * *Impact:* Same as above. Documentation consistency. * **`iam.md`**: * *Change:* Significant rewording regarding `forceLoginOrgUUID` and Console logins. * *Detail:* Added specific details about blocking behavior when the gateway is involved. * *Detail:* Clarified that Cloud provider sessions (like Bedrock) are now *blocked* if API keys are present (new behavior or clarified behavior?), whereas previously it said "not blocked". * *Impact:* This looks like a policy tightening or a clarification of how organization enforcement interacts with cloud provider credentials and API keys. * *Developer View:* Important for enterprise/managed environments. Login flow behavior changes. * **`llm-gateway.md`**: * *Change:* Clarified how saved claude.ai logins interact with gateway credentials. * *Detail:* Requests use the gateway credential *in place of* subscription login, but the saved login is kept locally. * *Impact:* Clarifies billing and auth flow. * *Developer View:* Better understanding of how billing/account switching works in gateway mode. * **`memory.md`**: * *Change 1:* Added a new command `/doctor prompt-audit` to check for outdated/conflicting instructions in CLAUDE.md files. * *Change 2:* Added advice on `includeGitInstructions` and `attribution` to avoid conflicts with built-in guidance. * *Impact:* New feature announcement (prompt audit tool). * *Developer View:* Very useful tool for maintaining large/complex projects with lots of config. * **`sub-agents.md`**: * *Change:* Added glossary link for "system reminder". * *Impact:* Documentation consistency. 3. **Synthesize and Structure (in Chinese):** * **Overall Summary:** These changes primarily clarify security/credential handling behaviors, introduce a new maintenance command for configuration files, and improve documentation consistency by adding glossary links. (这些更改主要阐明了安全和凭证处理行为,引入了用于维护配置文件的新命令,并通过添加词汇表链接提高了文档一致性。) * **Key Themes:** * **Security & IAM:** Strictened/clarified login enforcement rules, specifically how API keys and Cloud provider sessions interact with organization policies (`forceLoginOrgUUID`, `claude-apps-gateway`). * **Documentation Hygiene:** Added "system reminder" links across multiple pages. * **Tooling:** New `/doctor prompt-audit` command introduced. * **Cloud/Web Behavior:** Refined descriptions of credential filtering in bundles and gateway billing flow. * **Impact Level:** * *Level:* Medium. * *Reasoning:* While most are text clarifications or glossary links (Low impact), the `iam.md` changes regarding blocking cloud provider sessions and the new `/doctor` command in `memory.md` have practical significance for developers managing complex setups or enterprise policies. * **Action Items for Developers:** * Review IAM settings if using `forceLoginOrgUUID` with Cloud providers (Bedrock, etc.) to ensure access isn't unexpectedly blocked. * Try the new `/doctor prompt-audit` command to clean up project configuration files. * Update any internal documentation or training materials if the new credential enforcement logic affects your team's workflow. 4. **Drafting the Response (Iterative refinement for "World-class programmer" tone):** * *Drafting Summary:* Focus on the "new tool" and "IAM policy changes". * *Drafting Themes:* Group the IAM stuff together. Group the glossary stuff together. Highlight the new command. * *Drafting Impact:* Medium because of the IAM changes (potential breakage/access issues). * *Drafting Actions:* Check IAM, run doctor. 5. **Final Polish (Chinese):** * Ensure terms like "system reminder" are translated or kept as contextually appropriate (usually keep English tech terms in brackets if they are specific glossary entries). * Make the tone professional and concise. *(Self-Correction during drafting)*: The `iam.md` changes are quite detailed. The diff shows that Cloud provider sessions are now "blocked only while an API key... is still present". This is a behavior change from "not blocked". I need to emphasize this. 6. **Final Output Generation** (matches the provided good response).

📚 Claude Code

13:24 EST

🤖 AI Batch Analysis

## 文档变更分析 ### 1. 总体摘要 MCP tool hooks 的行为发生重要改进:从要求"已连接"改为"已配置"即可,且在阻塞性事件(如 `PreToolUse`、`Stop`)上会自动等待服务器连接完成;同时 `claude plugin validate` 新增了对 MCP 服务器配置和 shell 变量引用的校验能力。 ### 2. 关键主题 - **术语变更**:"already-connected MCP server" → "configured MCP server",反映了实际行为的放宽——不再要求服务器事先已连接 - **MCP hook 连接等待机制**:阻塞性事件上 Claude Code 现在会等待服务器连接(上限 `MCP_TIMEOUT`),观察性事件则不等待;`cached` 状态的服务器会在 hook 调用时按需连接 - **OAuth 限制明确化**:hook 不会触发 OAuth 流程,需事先通过 `/mcp` 认证 - **文档结构优化**:将原本内联的复杂说明拆分为三个独立小节(结果读取、连接中、事件时序),移除了冗长的 JSON 示例 - **插件校验增强**:`claude plugin validate` 新增 MCP 服务器条目检查(无效 URL、未声明 user_config 引用、非回环 http/ws、疑似凭据 header)以及 shell 变量未加引号的警告 ### 3. 影响级别:**Medium** 理由:核心行为变更——MCP tool hooks 在阻塞性事件上从"服务器未连接则跳过"变为"等待连接后再调用",这直接影响 hook 的执行时机和成功率。对于依赖 `SessionStart`/`Setup` 上 MCP hook 的开发者,行为不变(仍跳过),但对 `PreToolUse`/`Stop` 等,hook 成功调用的概率显著提高,无需额外操作。 ### 4. 开发者行动项 - **审查现有 MCP tool hooks**:如果你的 hook 绑定在 `PreToolUse`、`Stop` 等阻塞性事件上,现在执行时会等待服务器连接,可能引入额外延迟;必要时调整 `timeout` 设置 - **确保远程 MCP 服务器已认证**:hook 不触发 OAuth 流程,需在 `/mcp` 中预先完成认证,否则 `cached` 状态的服务器可能连不上导致非阻塞错误 - **升级到 v2.1.281+** 以获得 `claude plugin validate` 对 MCP 服务器配置的校验能力,在 CI 中用 `--strict` 捕获所有问题 - **检查插件中的 shell-form hook 命令**:确保路径变量(如 `${CLAUDE_PLUGIN_ROOT}`)被双引号包裹,否则 validate 将发出警告 - **不要在 `SessionStart`(启动时)或 `Setup` 上使用 `mcp_tool` hook**:它们仍会被跳过,改用 `type: "command"` 实现启动时的逻辑
💭 Model Reasoning
Let me analyze the documentation changes across the three pages. 1. **hooks.md** (+13/-15): Major changes to MCP tool hooks documentation: - Changed "already-connected" to "configured" MCP server terminology - Restructured the MCP tool hook fields table (removed inline description about server connection/OAuth from the `server` field) - Added new subsections: "How the tool's result is read" and "When the server is still connecting" and "Events that fire before MCP servers are available" - Key behavioral change: Claude Code now **waits** for connecting servers on blocking events (PreToolUse, Stop) up to MCP_TIMEOUT, rather than just skipping. On observational events, it doesn't wait. - Clarified that cached-status servers connect on-demand when the hook calls the tool - Simplified the SessionStart/Setup explanation - removed the verbose example with JSON config - Added note that hook never starts OAuth flow 2. **hooks-guide.md** (+1/-1): Terminology change matching hooks.md - "already-connected" → "configured" 3. **plugins-reference.md** (+5/-1): - `claude plugin validate` now checks MCP server entries (requires v2.1.281+) - Errors: dropped entries, bad user_config refs, invalid URLs - Warnings: http:// or ws:// to non-loopback, credential-like headers - Changed description of plugin data directory deletion on uninstall - Added warning about unquoted variables in shell-form commands Key themes: - MCP tool hooks behavior refined: now waits for connecting servers on blocking events - Terminology shift: "already-connected" → "configured" (reflects that servers can be in connecting/cached state) - Plugin validation enhanced with MCP server checks - Better documentation structure (subsections instead of inline explanations) Impact: Medium - the behavioral change (waiting for servers on blocking events) is significant for developers using MCP tool hooks, as it changes when hooks succeed vs. get skipped. The terminology change reflects a real behavioral improvement.

📚 Claude Code