Agent Frameworks & Harnesses 2026-10-03

Framework Watch: Claude Code 2.1.288 Closes a bypassPermissions rm Gap and Stops Oversized MCP Results From Running Tools Twice

Released October 2 (18:30 UTC), 2.1.288 is mostly fixes. Five matter for anyone running Claude Code unattended or behind MCP servers: a dangerous rm inside bash -c that ran without a prompt, duplicated MCP tool calls, a BASHPID permission gap, a false login success, and a retry watchdog that now gives up.

Anthropic published Claude Code 2.1.288 to npm at 18:30 UTC on October 2, 2026, a day after 2.1.287. The changelog runs to about 60 items, almost all fixes. These are the ones operators should act on.

  • Dangerous rm in a nested shell. A destructive rm, such as one on / or the home directory, inside a bash -c or sh -c script could run without a prompt in bypassPermissions mode or under a shell allow rule (issue #96300). If you run in that mode or allow bash broadly, upgrade first and check whether your guardrails relied on that prompt.
  • MCP tools running twice. MCP tool calls sometimes executed twice when a remote server's result was over 16 MB or could not be parsed. For tools with side effects -- creating tickets, sending messages, writing records -- that meant duplicates. Check logs for doubled actions on servers that return large payloads.
  • BASHPID permission check. The Bash permission check now prompts before a BASHPID assignment whose value the shell would evaluate as arithmetic, which it previously allowed silently.
  • False login success. /login could report "Login successful" when credentials could not be saved to secure storage. It now shows the failure and offers a retry.
  • Retry watchdog limit. Unattended sessions using CLAUDE_CODE_RETRY_WATCHDOG could retry for hours after a very long response stream failed. Claude Code now streams again and gives up after three timeouts, so supervisors should expect a clean failure instead of a hang.

Other changes worth knowing: mid-response API timeouts no longer fail the turn in non-interactive sessions and subagents, which now continue from the partial response; LSP requests time out after 60 seconds instead of hanging; an MCP server that asks for more OAuth scope mid-call now triggers a re-authentication prompt; and CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS turns off structured outputs for gateways that reject them.

Analysis: the pattern across the last three releases is hardening for unattended use -- retry caps, redaction, timeouts and now permission edge cases. The rm fix is the reminder that matters: a permission prompt is only as good as the parser that decides when to show it. Teams running agents with broad shell permissions should keep an independent backstop, such as a sandbox, a read-only mount or a filesystem snapshot, rather than relying on the harness to catch every destructive command.

Claude Code 2.1.288 fixes an unprompted destructive rm inside nested shells under bypassPermissions, duplicate MCP tool calls on oversized results, and an endless retry loop -- a reminder that unattended agents need a sandbox backstop beyond the harness's own prompts.