Anthropic published Claude Code 2.1.288 to npm at 18:30 UTC on October 2, 2026, a day after 2.1.287. The changelog runs to about 60 items, almost all fixes. These are the ones operators should act on.
- Dangerous
rmin a nested shell. A destructiverm, such as one on/or the home directory, inside abash -corsh -cscript could run without a prompt in bypassPermissions mode or under a shell allow rule (issue #96300). If you run in that mode or allowbashbroadly, upgrade first and check whether your guardrails relied on that prompt. - MCP tools running twice. MCP tool calls sometimes executed twice when a remote server's result was over 16 MB or could not be parsed. For tools with side effects -- creating tickets, sending messages, writing records -- that meant duplicates. Check logs for doubled actions on servers that return large payloads.
- BASHPID permission check. The Bash permission check now prompts before a
BASHPIDassignment whose value the shell would evaluate as arithmetic, which it previously allowed silently. - False login success.
/logincould report "Login successful" when credentials could not be saved to secure storage. It now shows the failure and offers a retry. - Retry watchdog limit. Unattended sessions using
CLAUDE_CODE_RETRY_WATCHDOGcould retry for hours after a very long response stream failed. Claude Code now streams again and gives up after three timeouts, so supervisors should expect a clean failure instead of a hang.
Other changes worth knowing: mid-response API timeouts no longer fail the turn in non-interactive sessions and subagents, which now continue from the partial response; LSP requests time out after 60 seconds instead of hanging; an MCP server that asks for more OAuth scope mid-call now triggers a re-authentication prompt; and CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS turns off structured outputs for gateways that reject them.
Analysis: the pattern across the last three releases is hardening for unattended use -- retry caps, redaction, timeouts and now permission edge cases. The rm fix is the reminder that matters: a permission prompt is only as good as the parser that decides when to show it. Teams running agents with broad shell permissions should keep an independent backstop, such as a sandbox, a read-only mount or a filesystem snapshot, rather than relying on the harness to catch every destructive command.
Claude Code 2.1.288 fixes an unprompted destructive rm inside nested shells under bypassPermissions, duplicate MCP tool calls on oversized results, and an endless retry loop -- a reminder that unattended agents need a sandbox backstop beyond the harness's own prompts.