Agent Frameworks & Harnesses 2026-10-07

Framework Watch: Claude Code 2.1.292 Closes a UNC-Path Prompt Bypass; Copilot Studio Hooks Arrive -- and Fail Open

Claude Code 2.1.292 (October 6) adds a per-subagent effort setting and fixes a set of permission edges, including PreToolUse hook approvals and auto mode skipping the prompt for reads from network paths. Microsoft's new Copilot Studio hooks, reported October 6, give low-code agents lifecycle events -- but only the pre-tool event can block, and a failed hook lets the agent carry on.

Two agent harnesses changed how lifecycle checks work this week. Anthropic shipped Claude Code 2.1.291 (03:55 UTC) and 2.1.292 (18:59 UTC) on October 6, 2026. Microsoft's Copilot Studio hooks preview, documented on Microsoft Learn on September 29, was reported by Cloud Wars on October 6.

Claude Code 2.1.292: what operators should act on

  • Prompt bypass on network paths. Marked as a security fix: "PreToolUse hook approvals and auto mode bypassing the permission prompt for file reads from network (UNC) paths."
  • Other permission edges. rm -rf on the 8.3 short name or another alternate Windows spelling of the home folder or a drive is now treated as removing it. A tampered on-disk cache of server-managed settings could switch off the built-in policy plugin while the settings fetch failed. Subagents with permissionMode: auto no longer enter auto mode when it is unavailable, and a skill's allowed-tools rule no longer returns after leaving auto or plan mode mid-turn.
  • New controls. An effort parameter on the Agent tool runs a sub-agent at a chosen effort level; CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS lengthens backoff on 529 errors; claude plugin install --marketplace adds a marketplace under the same policy checks as adding it directly.
  • Reliability. One-shot claude -p and Agent SDK runs now wait for background commands instead of stopping them five seconds after the result; Grep and Glob no longer report "no matches" on an unreadable path. 2.1.291, earlier the same day, fixed cloud sessions dropping answers to permission prompts.

Copilot Studio hooks: what developers are building, and the catch

Hooks bind a published workflow to an agent lifecycle event: session start, each user message, before a tool runs, after a tool succeeds, after a tool fails, and on other errors. Microsoft's examples are adding context such as open support cases at session start, blocking a tool call that breaks a business rule, redacting or auditing tool results, and telling the agent to retry, skip or stop on failure. Unlike a tool, which runs when the agent decides it is relevant, a hook runs every time its event fires.

Microsoft's documentation states two limits plainly. "Pre tool use is the only event that can block an action." And "Hooks don't stop the agent when they fail. If a workflow fails, times out, or returns something the agent can't read, the agent continues as though the hook returned nothing. Don't rely on a hook as your only safeguard for a business-critical rule." It also tells builders to treat hook inputs as untrusted, since prompts and tool results "can contain content the agent didn't produce."

Analysis: both releases point at the same design question -- what happens when the check itself fails or is routed around. Claude Code's fixes close paths where an approval skipped the prompt; Copilot Studio's hooks are fail-open by design. Teams using hooks for policy should keep a second, fail-closed control (permissions on the connector or data source) for anything that must not happen.

Claude Code 2.1.292 (October 6) fixes a UNC-path prompt bypass and several Windows and managed-settings permission edges while adding per-subagent effort; Copilot Studio's new hooks give low-code agents lifecycle checks but only pre-tool hooks can block and failed hooks fail open, so they shouldn't be the only guard on critical rules.