← All reports

Changes on 2026-10-02

60 total changes in 5 runs

21:39 EST

🤖 AI Batch Analysis

## 文档变更批量分析 ### 1. 总体概述 此次文档更新主要围绕**移除过时的版本门槛说明**(多个 "As of v2.1.199" 标注被清除)、**CLI 命令简化**(`claude project purge` → `claude purge`)、以及**auto-compact 窗口的按模型存储重构**展开,同时新增了插件请求超时配置和 skill 覆盖内置命令的能力。 ### 2. 关键主题 - **版本门槛清理**:大量 v2.1.199 相关的版本要求说明被移除(sandboxing、hooks、mcp、skills、sub-agents),表明这些功能已成为基线特性,不再需要版本提示 - **CLI 命令简化**:`claude project purge` 缩短为 `claude purge`,降低了使用摩擦 - **auto-compact 按模型配置**:`/autocompact` 现在将窗口值保存到当前模型的 `modelSettings` 下,而非全局 `autoCompactWindow`;同时新增环境变量 `CLAUDE_CODE_AUTO_COMPACT_WINDOW` 用于网关场景 - **skill 优先级扩展**:自定义 skill 现可覆盖内置命令(如 `/usage`),但不会覆盖其别名(如 `/cost`) - **插件 MCP 服务器超时**:新增 `requestTimeout` 字段(默认 60s,需 v2.1.288+) - **权限行为细化**:浏览器权限改为按站点记忆;headless 模式下 `"ask"` 的 reason 会传递给 Claude;`idle_prompt` 在后台子代理运行时不再触发 - **文档格式修复**:setup.md 中重复的 `theme={null}` 属性被清理 ### 3. 影响级别:**Medium** - **无破坏性变更**,但 `claude purge` 替代 `claude project purge` 属于命令重命名,旧命令可能仍可用但应迁移 - auto-compact 存储位置从全局改为按模型,已保存的设置可能需要重新配置(v2.1.288 前的行为已文档化) - 版本门槛的移除对开发者无负面影响,仅简化阅读 ### 4. 开发者行动项 - **迁移 `claude project purge` → `claude purge`**:更新脚本和肌肉记忆中的命令调用 - **检查 auto-compact 配置**:升级到 v2.1.288+ 后,`/autocompact` 将按模型保存窗口值;如需全局设置,改用 `autoCompactWindow` 配置项或 `CLAUDE_CODE_AUTO_COMPACT_WINDOW` 环境变量 - **利用 skill 覆盖内置命令**:现在可在 `.claude/skills/` 中创建与内置命令同名的 skill 来替换其行为(别名仍走内置) - **配置插件请求超时**:对响应慢的 MCP 服务器,在插件配置中设置 `requestTimeout`(毫秒)以替代默认 60s - **注意浏览器权限粒度变化**:权限提示现在按站点区分,已允许的站点不再重复询问,依赖旧行为的自动化脚本可能受影响
💭 Model Reasoning
Let me analyze all the documentation changes across the 11 pages. Key changes I see: 1. **chrome.md**: Clarification that browser permission prompts only appear for sites you haven't already allowed (more granular permission model). 2. **cli-reference.md**: - `claude project purge` → `claude purge` (simplified command) - Removed version-specific note about `--dangerously-skip-permissions daemon` behavior (v2.1.199) 3. **hooks.md**: - Clarified `permissionDecisionReason` behavior for `"ask"` in `-p` (headless) runs - Removed "As of v2.1.199" prefix for MCP tool requiresUserInteraction - `idle_prompt` now accounts for background agents/subagents still running 4. **mcp.md**: - Removed version requirement note for `anthropic/requiresUserInteraction` (v2.1.199) - Simplified URL mode description (removed "opens it when you accept") 5. **model-config.md**: - Auto-compact window now settable via `CLAUDE_CODE_AUTO_COMPACT_WINDOW` env var for gateway scenarios - `/autocompact` now saves per-model under `modelSettings` instead of global `autoCompactWindow` - Added new "For every model" setting option via `autoCompactWindow` in settings files - Before v2.1.288 note about the old behavior 6. **plugins-reference.md**: Added `requestTimeout` field for plugin MCP servers (default 60s, requires v2.1.288) 7. **sandboxing.md**: - Removed version requirement notes (v2.1.199 for masking env vars, v2.1.199 for tlsTerminate) - Consolidated credential masking description 8. **setup.md**: Fixed duplicate `theme={null}` attributes in code blocks (formatting fix) 9. **skills.md** / **slash-commands.md** (duplicate changes): - Added "built-in commands" to the name conflict resolution table - New row: skills can replace built-in commands in local terminal sessions (but not their aliases) - `effort` field now uses effort resolution order instead of "inherits from session" - Removed "Before v2.1.199" note about skill stacking - Removed "As of v2.1.199" prefix for `skillOverrides: "off"` behavior 10. **sub-agents.md**: - Removed "As of v2.1.199" prefixes for API error reporting and SendMessage name checking - These features are now standard, not version-gated Overall themes: - **Removing version-gated language**: Many "As of v2.1.199" and version requirement notes are being removed, suggesting these features are now baseline/standard - **CLI simplification**: `claude project purge` → `claude purge` - **Per-model auto-compact**: Significant change to how auto-compact windows are saved (per-model vs global) - **New features**: `requestTimeout` for plugins, skills overriding built-in commands - **Bug fixes**: Duplicate theme attributes in setup.md - **Behavior clarifications**: Browser permissions per-site, idle_prompt with background agents, permissionDecisionReason in headless mode
18:46 EST

🤖 AI Batch Analysis

# 文档变更批量分析 ## 1. 总体总结 本次变更主要围绕 Claude Code v2.1.288 的大量 bug 修复和若干行为调整,重点修改了交互式会话中后台命令的时间限制策略、`PermissionRequest` 钩子的触发范围、路径作用域规则的触发条件,以及 Amazon Bedrock/Mantle 的模型路由逻辑。 ## 2. 关键主题 - **后台命令时间限制大幅放宽**:本地交互式会话(终端、桌面应用、VS Code 扩展)中的后台命令不再有超时限制,仅无人值守会话(`-p`、云会话)保留时间限制 - **权限钩子行为细化**:`PermissionRequest` 钩子现在也会与 `--permission-prompt-tool` 和 Agent SDK 的 `canUseTool` 回调并行运行,先决定者生效;非交互模式下仍会在 `dontAsk` 模式之外运行 - **路径作用域规则触发扩展**:`.claude/rules` 中的路径作用域规则现在在 **Read、Write、Edit** 三种工具触发时都会加载(此前仅 Read 触发) - **Bedrock/Mantle 路由更精确**:`anthropic.` 前缀的条目仅在匹配 Mantle 格式时才路由到 Mantle 端点,而非全部路由;模型选择器行为按提供商差异化说明 - **安装与版本通道**:新模型可能需要 `latest` 通道;Linux 包管理器通过仓库选择通道 - **v2.1.288 大量修复**:超过 50 项 bug 修复,涵盖会话恢复、结构化输出、权限判断、插件、云会话、遥测等多个领域 ## 3. 影响级别:**Medium** 理由:后台命令时间限制的移除是行为显著变化,可能影响长时间运行任务的预期;路径作用域规则触发条件扩展可能让某些规则更频繁地加载;`PermissionRequest` 钩子与 SDK/CLI 权限机制的并行交互需要开发者理解新的优先级逻辑。但这些都不是破坏性变更,而是对先前行为的合理调整和细化。 ## 4. 开发者行动项 - **审查后台命令依赖**:如果你依赖交互式会话中后台命令的 30 分钟/2 小时超时来自动终止任务,需自行实现超时逻辑,因为现在交互式会话中不再有强制时间限制 - **更新路径作用域规则**:如果你的 `.claude/rules` 使用了 `paths` 字段,需注意规则现在会在 Write 和 Edit 操作时也触发,可能产生比预期更多的规则加载 - **检查 PermissionRequest 钩子**:若同时使用了 `--permission-prompt-tool` 或 Agent SDK 的 `canUseTool`,需理解钩子与这些机制并行运行、先决定者生效的新行为 - **验证 Bedrock 模型路由**:若在 `availableModels` 中使用 `anthropic.` 前缀条目,确认它们是否符合 Mantle 格式——只有匹配的才会路由到 Mantle 端点 - **升级到 v2.1.288**:本次包含关键修复(API 超时续传、会话恢复丢失上下文、`--resume` 丢文件、Mantle/网关结构化输出失败等),强烈建议升级
💭 Model Reasoning
Let me analyze these documentation changes as a batch. The changes span across 10 pages and include several important updates to Claude Code's documentation. Let me identify the key themes and impacts. 1. **Amazon Bedrock / Mantle routing changes**: The `anthropic.` prefix entries are now only routed to Mantle if they match the Mantle format, not automatically. Model picker behavior differs by provider. 2. **Hooks / Permission behavior changes**: `PermissionRequest` hooks now run alongside `--permission-prompt-tool` and Agent SDK's `canUseTool` callback. The behavior in non-interactive mode is clarified - hooks still run outside `dontAsk` mode. 3. **Background command time limits**: Major change - background commands in local interactive sessions (terminal, desktop app, VS Code) now have NO time limit. Only unattended sessions (`-p` runs, cloud sessions) have time limits. 4. **Path-scoped rules triggering**: Rules now trigger on Read, Write, or Edit tool usage (not just Read). 5. **Setup/installation**: New info about newly launched models requiring the latest channel, and Linux package managers choosing channel by repository. 6. **Subagent definitions**: Clarified that subagent definitions can be reused as agent team teammates. 7. **VS Code**: Removed mention of time limit for background commands moved to background (consistent with the interactive-mode change). 8. **Changelog**: Huge list of fixes and improvements for v2.1.288. Key themes: - Permission/hook behavior refinement - Background command time limit relaxation for interactive sessions - Model picker behavior clarification by provider - Path-scoped rules now trigger on Write/Edit (not just Read) - Many bug fixes Impact: Medium - the background command time limit change is significant (removing limits for interactive sessions), and the path-scoped rules triggering on Write/Edit is a behavior change. The permission hook changes are also notable for SDK users. Action items: - If you rely on background command time limits in interactive sessions, note they're now unlimited - If you use path-scoped rules, note they now trigger on Write/Edit too - If you use PermissionRequest hooks with --permission-prompt-tool or Agent SDK, review the new interaction - If you use Amazon Bedrock with anthropic. prefix models, verify routing still works (now only Mantle-format ones route to Mantle) - Upgrade to 2.1.288 for the many bug fixes

📚 Claude Code

📚 Claude Code GitHub

14:54 EST

🤖 AI Batch Analysis

### 总体摘要 本次更新主要集中在 **Chrome 浏览器集成**的工作流优化、**Amazon Bedrock** 平台 API 功能限制的澄清,以及对 **状态栏监控**和 MCP 动态更新机制的技术细节完善。同时,文档清理了对旧版本 (v2.1.198) 的依赖说明,标志着该版本已成为新的基准线。 ### 关键变更主题 * **Chrome 与 VS Code 深度集成优化**: * 明确了 VS Code 会话中浏览器的连接逻辑:v2.1.287 版本支持会话启动时自动连接。 * 细化了权限提示行为:根据连接方式(手动输入 `@browser` 或默认设置自动连接),Claude 请求权限的规则有所不同。 * 更新了 `/diff` 工具的描述,区分了全屏渲染中的“Diff 面板”与经典渲染中的“Diff 对话框”,并指出了新版本要求。 * **Amazon Bedrock 平台关键限制**: * 明确指出**结构化输出** 仅在 Amazon Bedrock 的**传统集成** 中可用,新的“Claude in Amazon Bedrock”集成暂不支持此功能。 * **监控与可观测性增强**: * 状态栏 API 新增了 `used_usd`、`limit_usd` 和 `period` 字段,允许开发者更精确地监控通过 Claude Apps Gateway 的费用支出。 * 阐明了 MCP 工具在恢复会话期间调用时的等待机制,以及动态工具更新在非交互模式和 SDK 中的特定行为。 * **文档基准版本更新**: * 移除了多处关于 "v2.1.198 或更高版本" 的说明,暗示 v2.1.198 已成为当前支持的基础版本。 ### 影响等级:**中等** **理由**:对于大多数 Claude Code 用户而言,本次变动主要是体验优化和文档澄清。然而,对于 **Amazon Bedrock 用户**,结构化输出的可用性限制属于**高影响**信息,直接影响架构选择。此外,依赖状态栏脚本进行成本监控的开发者需要适配新的数据字段。 ### 开发者行动项 1. **检查 Bedrock 集成方式**:如果您在 Amazon Bedrock 上使用结构化输出,请确认您使用的是**传统集成**;新的“Claude in Amazon Bedrock”集成目前不支持该功能。 2. **更新成本监控脚本**:如果您编写了自定义状态栏脚本来监控 `spend_limit`,请更新代码以解析新增的 `used_usd` 和 `limit_usd` 字段(需 v2.1.284+)。 3. **审查 Chrome 权限逻辑**:如果您在 VS Code 中使用 Claude Code 浏览器功能,请留意当前会话是否由“默认启用”连接的,这决定了 Claude 执行操作前是否会请求权限。
💭 Model Reasoning
1. **Analyze the Request**: * **Role**: World-class programmer analyzing documentation changes. * **Output**: Concise, insightful analysis in markdown format. * **Content**: A single batch of 16 changed pages with diffs. * **Language**: Chinese. * **Focus**: What matters to developers. 2. **Scan the Diffs (Page by Page)**: * `chrome.md`: * *Changes*: Updated instructions for "Enable Chrome by default". Clarifies CLI vs. VS Code behavior. Explicitly mentions version v2.1.287 for VS Code auto-connect. Added section on "Permission prompts in VS Code sessions" (behavior depends on how connection was established: `@browser` vs default setting). Refined "Browser tools in plan mode". * *Why it matters*: Developers using Chrome integration need to know the specific permission behaviors in VS Code sessions, as they differ based on connection method. Version dependency highlights. * `cli-reference.md`: * *Changes*: Minor text fix in `--print` description ("Resume a running background session" instead of "Resume a session"). * *Why it matters*: Very low impact, just a clarification. * `desktop.md`: * *Changes*: Moved "Auto mode availability" section into an `h4` tag with an ID. Removed redundant "Auto mode is available..." block (consolidated). * *Why it matters*: Structural change, likely for better linking/rendering. Low impact. * `hooks.md`: * *Changes*: Removed specific version requirement mentions for v2.1.198 (subagent status, PowerShell rewrite, agent_needs_input types). Rewrote PowerShell placeholder explanation to remove "As of v2.1.198". * *Why it matters*: The tool likely considers v2.1.198 as the baseline now, so version checks are removed. Developers can assume these features exist in the current stable version. * `hooks-guide.md`: * *Changes*: Removed "require Claude Code v2.1.198 or later" note for `agent_needs_input` and `agent_completed` matchers. * *Why it matters*: Same as `hooks.md`, version requirements cleaned up. * `interactive-mode.md`: * *Changes*: Cleaned up `/diff` command description. Clarified behavior in Fullscreen vs Classic renderer. Added specific version requirement (v2.1.287) for the diff panel. Added `cc-plugin-diff` context. Changed "diff viewer" to "diff dialog". Added details on how to ask Claude about changes via the "ask" button. * *Why it matters*: UI changes for diffing. Users need to know the distinction between panel/dialog and version requirements. * `mcp.md`: * *Changes*: Clarified behavior when resuming sessions with MCP tools connecting. Added "Dynamic tool updates" explanation distinguishing interactive vs non-interactive/Agent SDK behavior. * *Why it matters*: Important for plugin/MCP developers. The distinction between interactive and SDK modes for dynamic updates is crucial for server implementation. * `monitoring-usage.md`: * *Changes*: Refined OTEL logging explanation for background WebFetch/WebSearch. Added reference to `priority` field in Agent SDK. * *Why it matters*: Debugging telemetry. Helps understand why some tool spans might be missing in logs. * `setup.md`: * *Changes*: Updated Bash tool description to mention Monitor tool requirement. Removed "As of v2.1.198" for npm Node.js requirement. * *Why it matters*: Hardware/Environment setup clarity. * `statusline.md`: * *Changes*: Added `used_usd`, `limit_usd`, `period` fields to `rate_limits.spend_limit`. Added examples in shell scripts (Bash/Python/JS) to display these new fields. * *Why it matters*: Developers building custom statusline integrations or cost monitoring scripts need to update their code to parse these new financial fields. * `sub-agents.md`: * *Changes*: Reorganized "Inline server trust" section. Consolidated info on MCP restrictions and trust requirements. Removed "As of v2.1.198" note regarding `/agents` wizard removal. * *Why it matters*: Security/Permissions. Crucial for developers defining agents with inline MCP servers to understand trust boundaries. * `vs-code.md`: * *Changes*: Added link to "Enable Chrome by default" and "Permission prompts in VS Code sessions". * *Why it matters*: Cross-linking for better UX. * `build-with-claude/overview.md`, `build-with-claude/text-generation.md`: * *Changes*: Table formatting looks identical in diff (copy-paste issue?). *Correction*: The diff shows these pages have huge tables but the diff context provided cuts off. Looking closely at the snippet: It shows the table headers. Actually, the diff provided in the prompt seems to be truncated or identical for both pages in the viewable section. I will treat them as table updates or reference updates if visible, but the provided text is mostly just the top of the table. *Re-reading*: The diff shows the start of the table. It seems to be a formatting update or maybe a content update at the bottom not shown. However, `claude-on-amazon-bedrock.md` and `structured-outputs.md` have specific changes. * `build-with-claude/structured-outputs.md`: * *Changes*: Updated Amazon Bedrock note to distinguish between "Legacy Bedrock" and "Claude in Amazon Bedrock". Structured outputs are legacy only. * *Why it matters*: **High Impact**. Breaking/Critical clarification. Developers using the new Bedrock integration cannot use structured outputs in the same way (or at all on the new one yet). This is a vital platform distinction. * `build-with-claude/claude-on-amazon-bedrock.md`: * *Changes*: Updated Structured outputs compatibility note to link to legacy integration. * *Why it matters*: Same as above. Cross-referencing the limitation. 3. **Synthesize and Structure**: * **Overall Summary**: The documentation updates focus on refining user experience for Chrome/VS Code integration, clarifying version baselines (removing outdated v2.1.198 checks), and updating platform-specific feature availability, particularly regarding Structured Outputs on Amazon Bedrock. * **Key Themes**: * *Chrome/VS Code Integration*: New connection behaviors (v2.1.287) and permission prompt logic based on connection method (`@browser` vs default). * *Platform API Specifics*: Critical distinction for Amazon Bedrock (Legacy vs. New) regarding Structured Outputs support. * *Version Cleanup*: Removal of "As of v2.1.198" notes, implying v2.1.198 is now the minimum supported version. * *Tooling & Monitoring*: New financial fields in statusline (spend limits), refined Diff tooling descriptions, and MCP dynamic update behavior. * **Impact Level**: **Medium** (High for Bedrock users, Low/Medium for general Claude Code users). * *Reasoning*: Most changes are clarifications or version cleanups. However, the Amazon Bedrock Structured Outputs note is a critical limitation for API developers. The Chrome/VS Code permission changes affect daily workflow. * **Action Items**: * Check if using Amazon Bedrock: verify if you are on the legacy integration if you need Structured Outputs. * Update statusline scripts if monitoring spend limits (new USD fields available). * Review Chrome integration logic if you rely on specific permission flows in VS Code. 4. **Drafting the Response (in Chinese)**: * *Translation*: * "Chrome by default" -> "Chrome 默认启用" * "Structured Outputs" -> "结构化输出" * "Amazon Bedrock" -> "Amazon Bedrock" * "MCP" -> "MCP" * "Statusline" -> "状态栏" * *Refining Action Items*: 1. Amazon Bedrock users: Check integration version for Structured Outputs. 2. Statusline scripters: Parse new `used_usd` fields. 3. Chrome users: Understand the `@browser` vs auto-connect permission difference. 5. **Final Review**: * Did I miss the "diff viewer" vs "diff panel" changes in `interactive-mode.md`? Added to key themes/impact (UX improvement/clarification). * Did I catch the MCP dynamic update nuance? Yes, added to themes. 6. **Final Output Generation** (Markdown format).

📚 Claude Code

09:28 EST

🤖 AI Batch Analysis

### Overall Summary 本次文档更新主要集中在安全策略细化与配置澄清,特别是“会话摘要”的触发限制、VS Code 扩展的诊断权限以及沙箱路径合并逻辑的调整。 ### Key Themes * **安全策略与隐私控制**:限制了自动会话摘要在第三方消息中继(如 Slack/Teams)中的触发;明确了 VS Code 新增诊断服务器的权限命名规则。 * **配置逻辑澄清**:修正了自动记忆在 AI 子会话中的开关行为;细化了沙箱文件系统路径合并时受“锁”机制影响的规则。 * **VS Code 扩展增强**:新增消息时间戳显示、`/model` 快捷指令,并引入了独立的内置诊断服务器。 * **环境配置修正**:明确 `ANTHROPIC_FOUNDRY_RESOURCE` 必须使用资源名而非 URL。 ### Impact Level **Medium** **Reasoning:** 虽然大部分更正属于文档澄清,但 `/recap` 行为的变更(自动场景下仅返回 Notice)以及 VS Code 诊断工具的新增权限ID(`mcp__claude-vscode__getDiagnostics`)直接影响了现有的安全控制和自动化流程。若配置未及时更新,可能导致自动化任务失败或权限管控出现漏洞。 ### Action Items for Developers * **审查自动化摘要依赖**:如果你在自动化脚本或第三方集成中依赖 `/recap`,请知晓它现在将返回提示而非实际摘要内容。 * **更新 VS Code 权限规则**:若之前通过权限规则阻止诊断工具读取错误信息,需在 `deny` 列表中增加 `mcp__claude-vscode__getDiagnostics`,因为单纯的 `Read` 拒绝规则无法覆盖它。 * **修正 Foundry 配置**:检查 `ANTHROPIC_FOUNDRY_RESOURCE` 环境变量,确保它只包含资源名(如 `my-resource`),移除任何 URL 或主机名前缀。 * **理解自动记忆的限制**:在由 Claude Code 启动的子会话(如通过 Bash 工具调用)中,无法通过开关开启自动记忆,必须在直接启动的会话中操作。 * **确认沙箱合并逻辑**:在配置多层级沙箱路径时,注意被“锁”覆盖的路径不会被合并,确保策略符合预期。
💭 Model Reasoning
1. **Analyze the Request:** * **Role:** World-class programmer analyzing documentation changes. * **Task:** Analyze a batch of 6 documentation diffs. * **Output:** Concise, insightful analysis in markdown, in Chinese. * **Structure:** Overall Summary, Key Themes, Impact Level, Action Items. 2. **Analyze the Diffs (Page by Page):** * **Page: `interactive-mode.md`** (+2/-2) * *Change:* Updated the section on "Session recap". * *Details:* Changed behavior: `/recap` only runs when asked *by the user*. If triggered via relay (Slack, Teams, project thread, routine), it shows a *notice* instead of the recap. Clarified that automatic recaps don't appear in non-interactive mode. * *Implication:* Security/Privacy feature. Prevents unintended information leakage via automated triggers. * **Page: `memory.md`** (+6/-1) * *Change:* Updated the section on "Auto memory". * *Details:* Clarified behavior of the toggle. In "background sessions" or sessions started by *another* Claude Code session (e.g., via Bash tool), the toggle shows "off · can't be turned on here; use a session started outside Claude Code". * *Implication:* Usability/Config nuance. Users can't enable memory within sub-sessions spawned by AI; they must use a top-level session. * **Page: `microsoft-foundry.md`** (+1/-0) * *Change:* Added clarification for `ANTHROPIC_FOUNDRY_RESOURCE`. * *Details:* Must be a resource name (e.g., `my-resource`), *not* a URL or host name. Added link to error docs. * *Implication:* Setup fix. Prevents configuration errors. * **Page: `sandboxing.md`** (+3/-3) * *Change:* Refined explanations for file system merging and port settings. * *Details:* 1. Merging filesystem arrays now excludes entries covered by a "lock" under "Keep developers from widening the policy". 2. Changed "resolves to the project root only when..." to "resolves to the project root when..." (minor grammar/precision). 3. Clarified precedence for setting ports: "The first case that matches applies." * *Implication:* Security/Sandboxing logic clarification. Crucial for enterprise/admins configuring policies. * **Page: `setup.md`** (+0/-3) * *Change:* Code block formatting cleanup. * *Details:* Removed duplicate `theme={null}` attributes in code blocks. * *Implication:* Cosmetic/Documentation quality. No functional change. * **Page: `vs-code.md`** (+16/-2) * *Change:* New VS Code extension features and bug fixes. * *Details:* 1. `/model` command now opens the picker directly (v2.1.284+). 2. New setting: `showMessageTimestamps` (v2.1.284+). 3. Clarification: `environmentVariables` setting ignores relative paths or `~` for `CLAUDE_CONFIG_DIR`. 4. New feature: Built-in diagnostics tool `claude-vscode` for the chat panel (v2.1.285+). It reads the Problems panel. 5. Security/Permissions: Hooks need to block `mcp__claude-vscode__getDiagnostics` alongside `mcp__ide__getDiagnostics`. `Read` deny rules don't work on these; use tool name denies. * *Implication:* Feature additions and critical permission updates for VS Code extension users. 3. **Synthesize and Structure (in Chinese):** * **Overall Summary:** * Focus: This update refines the behavior of "Session Recap" for security, clarifies configuration precedence in sandboxing and memory features, adds small UX improvements to the VS Code extension (timestamps, model picker), and introduces a new diagnostics mechanism. * Draft (CN): 本次文档更新主要涉及“会话摘要”的安全行为调整、沙箱与自动记忆配置逻辑的澄清,以及 VS Code 扩展的新增功能(时间戳、诊断工具)和配置限制。 * **Key Themes:** * Security/Policy Controls (Recap in relays, Sandbox merging logic, Diagnostics permissions). * Configuration Nuances (Auto memory in sub-sessions, Foundry resource names, Env var paths). * VS Code Extension Enhancements (Timestamps, `/model` shortcut, Diagnostics server). * **Impact Level:** * *Assessment:* Medium. While mostly clarifications, the change in how `recap` works in relayed messages and the new diagnostics permissions in VS Code affect security/privacy behaviors. The sandbox merging change is important for admins. * *Reasoning:* Breaking changes in logic (recap), new permission requirements for VS Code diagnostics, and specific config validations. * **Action Items:** * Check `recap` usage if relying on it in automated flows (it will fail/show notice). * Update VS Code permission hooks/deny rules if blocking diagnostics. * Verify `ANTHROPIC_FOUNDRY_RESOURCE` isn't a URL. * Be aware that auto memory cannot be toggled on in AI-spawned sessions. * Review `sandbox.filesystem` merging logic regarding "locks". 4. **Drafting the Response (Iterative refinement for tone and brevity):** * *Summary:* 本次更新主要集中在安全策略细化与配置澄清,特别是会话摘要的触发条件、VS Code 扩展的诊断权限以及沙箱路径合并逻辑。 * *Themes:* * 安全策略强化:限制了自动摘要在第三方集成(Slack/Teams)中的触发,明确了 VS Code 诊断工具的权限命名。 * 配置与沙箱逻辑:修正了自动记忆在子会话中的行为,细化了沙箱文件系统数组合并时的规则。 * VS Code 功能增强:新增消息时间戳显示、`/model` 快捷指令及内置诊断服务器。 * *Impact:* Medium。主要涉及行为变更和权限定义的补充,虽然代码未直接破坏,但配置和权限策略需相应调整。 * *Action Items:* * 检查是否依赖自动化场景下的 `/recap` 功能(现会返回 Notice)。 * 更新 VS Code 权限配置,若需阻止诊断,需同时拒绝 `mcp__claude-vscode__getDiagnostics`。 * 核查 `ANTHROPIC_FOUNDRY_RESOURCE` 变量是否为纯资源名而非 URL。 * 注意自动记忆在“后台会话”或 AI 启动的会话中无法开启。 5. **Final Polish (Markdown formatting):** Ensure headers and lists match the requested format. (Self-correction: Ensure specific version numbers like v2.1.284 are mentioned if relevant to impact, but keep it concise). * *Refining the "Recap" point:* It's a privacy/security change. Important. * *Refining the "Diagnostics" point:* New tool name added, existing `Read` deny rules don't cover it. This is a potential security gap if ignored. 6. **Final Output Generation** (matches the provided good response).

📚 Claude Code

02:35 EST

🤖 AI Batch Analysis

## 总体摘要 本次更新涉及 17 个页面,重点在于**强化安全隔离边界**(明确沙箱覆盖范围及云会话限制)、**修正部署与监控指南**(解决网络存储崩溃风险及 Token 指标统计口径),并优化了**插件管理与子代理模型**的行为逻辑。 ## 关键主题 * **安全隔离与权限细化**:大幅修订了沙箱文档,明确区分了哪些进程运行在沙箱内(如 Bash)与外(如 Hooks、MCP 服务器、用户手动输入的命令);同时修正了云会话中对 Git Push 的安全限制。 * **平台差异与行为修正**:明确了 Windows 原生环境在云会话上传时对敏感文件的处理方式与 Unix 系统不同;补充了 `--teleport` 在自动化场景下对 SSH 密码交互的处理限制。 * **部署稳定性与运维**:新增关于“网络存储安装”的警告,指出在 NFS 等共享存储上安装可能导致会话崩溃;补充了云会话上传所需的 Git 版本及仓库布局要求。 * **可观测性与计费准确性**:明确 `input_tokens` 指标**不包含**缓存读写部分,提供了符合 OpenTelemetry GenAI 语义规范的 Token 计算公式,修正了成本统计模型。 * **插件与模型配置**:理清了“插件更新”与“市场刷新”的区别;优化了 Explore 子代理在不同提供商(Anthropic vs 第三方)上的模型降级与回退行为。 ## 影响等级:高 **理由**: 1. **关键 Bug 风险**:`setup.md` 明确指出在网络共享存储(如 NFS)上安装二进制文件会导致运行时崩溃,这对企业级部署至关重要。 2. **计费与监控逻辑变更**:`monitoring-usage.md` 对 `input_tokens` 的定义变更直接影响成本核算,依赖现有指标的开发者需调整计算公式。 3. **安全模型变更**:沙箱与云会话限制的澄清可能影响现有的自动化脚本或 CI/CD 流程的权限配置。 ## 开发者行动项 1. **检查安装环境**:如果您的 Home 目录位于网络存储(NFS)上,请务必将 Claude Code 安装到本地磁盘,或确保旧版本二进制文件在所有会话结束后才被删除,以避免 `Bus error`。 2. **更新监控仪表盘**:在计算总 Token 成本时,务必将 `cache_read_tokens` 和 `cache_creation_tokens` 加到 `input_tokens` 上,以符合 OpenTelemetry 标准并获得准确计费。 3. **审查防火墙规则**:若您使用 MCP Apps 或相关组件,请将 `*.claudemcpcontent.com` 加入白名单,以确保交互式组件能正常加载。 4. **验证自动化脚本**:使用 `--teleport` 的自动化脚本需预先加载 SSH 密钥至 `ssh-agent`,因为新版本不再等待终端输入密码。 5. **注意 Windows 云上传安全性**:在 Windows 原生环境下使用 `--cloud` 时,未提交的更改(包括敏感文件)会被直接上传,建议在启动会话前进行 stash 或 revert。
💭 Model Reasoning
1. **Analyze the Request**: * **Role**: World-class programmer, expert in developer tools/documentation. * **Task**: Analyze a batch of 17 documentation changes. * **Output**: Concise, insightful analysis in Markdown format (Chinese). * **Structure**: 1. Overall Summary, 2. Key Themes, 3. Impact Level, 4. Action Items. 2. **Analyze the Changes (Page by Page)**: * `claude-code-on-the-web.md`: * Changes: Clarified repository bundling (what's included/excluded). Specifically, native Windows behavior regarding sensitive files is different from macOS/Linux/WSL (uploads uncommitted changes to tracked files regardless of name). Added detailed requirements for git version and checkout layout. Clarified `--teleport` behavior regarding SSH/Git password prompts (it never waits for input). * *Implication*: Security nuance (Windows vs. Unix). Platform-specific requirements for cloud sessions (`--cloud`). Better handling of automated workflows involving SSH keys/passphrases. * `discover-plugins.md`: * Changes: Clarified plugin updating. No "update all at once" command for individual plugins, but "Update marketplace" updates plugins from that specific marketplace. Note: `claude plugin marketplace update` only refreshes listings, doesn't update plugins. * *Implication*: Clarifies plugin management workflow, preventing confusion about bulk updates. * `hooks-guide.md`: * Changes: Minor wording change ("handles" vs "hooks"). Not a huge functional shift. * *Implication*: Negligible. * `interactive-mode.md`: * Changes: Updated reference link for strict sandbox mode. Refined the UI text and behavior for "Usage limit reached" automatic continuation. Better handling of sleep/wake states and resumption. * *Implication*: UX improvements for long-running tasks and usage limit handling. * `mcp.md`: * Changes: Updated install instructions to differentiate between VS Code/Desktop/CLI. Added info on `/mcp reconnect all` for failed servers. * *Implication*: Fixes installation confusion, adds recovery command for MCP connectivity. * `model-config.md`: * Changes: Clarified Opus fallback behavior on non-Anthropic providers (uses `ANTHROPIC_DEFAULT_OPUS_MODEL` env var or Opus 5). Added section "Effort level after a fallback" - explains how effort persists across model fallbacks. * *Implication*: Predictability in model selection and effort levels when automatic fallback occurs. * `monitoring-usage.md`: * Changes: Clarified `input_tokens` metric definition: it *excludes* cache tokens (read/write). Added mapping to OpenTelemetry GenAI semantic conventions (calculating total input tokens by adding cache tokens). * *Implication*: High impact for observability/metrics. Corrects potential misunderstandings about cost/token counting. * `network-config.md`: * Changes: Added `*.claudemcpcontent.com` to required hosts for MCP Apps widgets. * *Implication*: Network/firewall configuration update for enterprise users. * `plugins.md`: * Changes: Added a note clarifying that VS Code/JetBrains extensions are different from "Claude Code plugins". * *Implication*: Reduces terminological confusion. * `plugins-reference.md`: * Changes: Clarified JSON structure for hooks in manifest (needs `"hooks"` wrapper). Added info on `experimental.evals` path rules. * *Implication*: Fixes plugin development issues regarding configuration syntax. * `sandboxing.md`: * Changes: Major rework/intro refinement. Clarified default permissions. Added explicit section "What runs outside the sandbox" (hooks, file tools, typed commands). Reorganized Linux/WSL setup info. * *Implication*: Improves security posture understanding. Critical for developers relying on the sandbox for safety. * `security.md`: * Changes: Updated "Branch restrictions" to "Push restrictions". Clarified that GitHub Proxy rejects non-branch pushes (tags) and how protection rules apply. * *Implication*: Security tightening/correctness. * `setup.md`: * Changes: Fixed code block formatting (`theme` attribute). Added major section on "Install on network storage" advising against shared network drives for home directories/binaries due to `Bus error`/crash risks during updates. * *Implication*: Critical for enterprise deployments with NFS/shared home drives. * `skills.md`: * Changes: Updated `skill-creator` plugin install instructions (same as MCP). * *Implication*: Consistency. * `sub-agents.md`: * Changes: Refined "Explore" subagent model behavior. Now specifically states Explore runs on Opus (via alias) for Claude subscriptions/APIs, but stays on main model for third-party providers. Updated `CLAUDE_CODE_SUBAGENT_MODEL_FORCE` behavior details. * *Implication*: Cost control (Explore behavior) and predictability. * `vs-code.md`: * Changes: Added warning when opening a session already active elsewhere ("mix up messages"). Updated reload behavior continuation rules. Added validation for deep-link plugin installs (invalid URL handling). * *Implication*: Prevents data corruption from concurrent sessions. Better UX for plugin distribution. 3. **Synthesize Themes**: * *Platform Specificity*: Windows vs. Unix behavior (Sandbox, Cloud bundling). * *Security & Isolation*: What runs in sandbox vs outside, network domains, cloud push restrictions. * *Observability*: Clarifying token metrics (excluding cache). * *Deployment/Installation*: Network storage warnings, git version requirements. * *UX/Reliability*: Usage limit continuation, concurrent session warnings. 4. **Determine Impact Level**: * *High*: The network storage crash warning (`setup.md`) and the token metric definition change (`monitoring-usage.md`) are significant for operations and billing. * *Medium*: Sandbox security clarification, Git requirements for cloud, model fallback behavior. * *Low*: Wording tweaks, minor install instruction clarifications. * *Overall*: **High**. The network storage issue is a potential crash bug affecting enterprise deployments, and metric accuracy is crucial for cost monitoring. 5. **Draft Action Items**: * Check deployment environments (don't use network storage for binaries). * Update monitoring dashboards (formula for total tokens). * Review firewall rules (add `claudemcpcontent.com`). * Update SSH agent usage if using `--teleport` automation. * Clarify for Windows users regarding cloud bundling security. 6. **Final Review and Translation (Chinese)**: * *Summary*: 17 pages updated. Focus on security clarifications (sandbox/cloud), deployment stability (network storage), and observability (token metrics). * *Themes*: Platform-specific security, deployment reliability, metrics accuracy. * *Impact*: High (due to crash risk in network storage and billing metric changes). * *Actions*: 1. Avoid network storage for installs. 2. Update metrics logic. 3. Update firewall. 4. Check Git version requirements. 5. Review Windows cloud upload security. 7. **Construct Markdown Output**. (Proceeding to generate output based on these thoughts). * *Self-Correction during drafting*: Ensure the distinction between "Claude Code Plugin" and "VS Code Extension" is mentioned in the summary or themes as it helps mental model. Ensure the `input_tokens` exclusion is highlighted clearly. 8. **Final Polish**: Ensure tone is professional ("world-class programmer"). *(Self-Correction)*: The `monitoring-usage.md` change is quite technical regarding GenAI semantic conventions. I should mention that this affects how users calculate costs. Let's write it out. **Summary**: 此次更新涉及 17 个页面,主要集中在增强安全隔离边界、修复特定部署环境(如网络存储)的稳定性问题,以及明确计费指标的统计口径。 **Themes**: 平台差异(Windows vs Unix)、沙箱边界定义、部署稳定性、监控指标修正。 **Impact**: High。网络存储部署可能导致崩溃,且计费指标的定义变更直接影响成本分析。 **Actions**: 1. 避免在网络存储上安装。 2. 调整监控计算公式。 3. 检查防火墙规则。 4. 更新 Git 版本。 5. 注意 Windows 云上传的安全性。 Looks good. I will expand slightly in the final output for detail.