2.1.210
Claude Code 2.1.210 - リリースノート
2026年7月14日
Claude Code
日本語サマリー
以下は Claude Code 2.1.210 のリリースノートの要約です。
Claude Code 2.1.210 リリースノート要約
⚠️ 破壊的変更・セキュリティ修正
- セキュリティ強化: subagent が読み取ったコンテンツを経由した間接的なプロンプトインジェクションに対して、Agent ツールの防御を強化しました。
- 権限設定の変更(破壊的):
Write(path),NotebookEdit(path),Glob(path)の権限ルールは非推奨となりました。起動時に警告が出ます。代わりにEdit(path)またはRead(path)を使用してください。
主な変更点・新機能
- 長時間実行ツールの可視性向上: 折りたたまれたツール要約行にリアルタイムの経過時間カウンターを追加し、処理が進行中であることを明確にしました。
claude attachの安定化: セッション遷移時の「job not found」等のエラーを修正し、デーモンの安定を待機してからアタッチするよう改善了。git worktreeのクリーンアップ: 終了したバックグラウンドセッションが残していたgit worktree lockを、定期的なクリーンアッププロセスで解放するように修正しました。isolation: 'worktree'の修正: サブエージェントがメインリポジトリに対して誤って git の変更コマンドを実行してしまう問題を修正しました。- auto mode の改善: 外部セッションのパーミッション分類器がデフォルトで Sonnet 5 を使用するように改善されました(
/doctorの提案スキップも修正)。 - エディタ・UI表示の修正: 外部エディタに貼り付けた際に文字化け(È/É)が混入する問題や、bigint 値が返された際のセッションクラッシュを修正しました。
- 無人セッションの安定化: hook callback のタイムアウトがユーザーの拒否と誤判定され、無人セッションが停止する問題を修正しました。
- ** MEMORY.md のエラーハンドリング**:
MEMORY.mdのインデックスが読み取り制限を超えた場合、暗黙的に切り捨てられるのではなく、明示的なエラーを返すようにしました。 - アクセシビリティ向上: スクリーンリーダーモードで、
Shift+Tabによる権限モードの切り替え時に音声で変更内容が通知されるようになりました。
原文(Release Notes)
What's changed
- Added a live elapsed-time counter to the collapsed tool summary line so long-running tool calls visibly tick instead of looking stuck
- Added a startup warning for
Write(path),NotebookEdit(path), andGlob(path)permission rules — useEdit(path)orRead(path)instead- Fixed
isolation: 'worktree'subagents being able to run git-mutating commands against the main repo checkout instead of their own isolated worktree- Fixed the
ultracodekeyword opt-in firing on non-human-originated input such as webhook payloads and relayed PR comments- Fixed a rendered text fragment leaking into crash telemetry when a UI component returned content outside a styled text element
- Fixed paste markers leaking into external editors opened from Claude Code, which could appear as stray È/É characters around pasted text
- Fixed
claude attachsometimes failing with "job not found" or "agent is still starting" errors during session transitions — attach now waits for the daemon to settle, and terminal resizes during a slow attach are applied once it completes- Fixed a session crash when a tool's result renderer returned a numeric bigint value or plain text instead of a UI element
- Fixed a hook callback timeout being misreported to the model as a user rejection, which made unattended sessions stop and wait
- Fixed Claude assuming a
cdtook effect after its command was moved to the background; the tool result now states the working directory is unchanged- Fixed plugin-provided MCP servers being torn down when MCP servers are re-synced mid-session
- Fixed plan approvals without edits being labeled "(edited by user)" and overwriting the plan file with a stale snapshot
- Fixed
/doctorskipping its auto-mode-default proposal on Bedrock, Vertex, and Foundry, where auto mode no longer needs an opt-in- Fixed Grep content mode claiming "No matches found" when paginating past the end of results
- Fixed unmatched
$1/$2positional placeholders in skills and commands being silently stripped; they are now preserved verbatim- Fixed plugin cache writes leaving temp files behind on failure and failing on locked-file renames on Windows and network filesystems
- Fixed background workers crash-looping when a client resets its connection to the background service
- Fixed
claude agents --effort ultracodenot reaching dispatched sessions; the value was silently dropped- Fixed pressing ← to open the agents view dropping the task tracker when returning to the session
- Fixed the agents dashboard retaining pasted images from abandoned reply drafts after their session was deleted
- Fixed killed background sessions leaving a permanent
git worktree lockbehind; the periodic sweep now releases locks whose owning process is gone- Fixed SDK MCP servers registered via an
initializecontrol request waiting until the next turn to start connecting- Fixed returning to the agents view from a session leaving overlapping ghost frames with
CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN=1- Fixed late-appearing
.claude/*symlinks not being reconciled into the sandbox deny-write list- Hardened the Agent tool against indirect prompt injection via content a subagent read
- Improved the Bash/PowerShell tool message when a command hits its timeout and is auto-backgrounded, so the model can distinguish a hang from an explicit background request
- Improved auto mode: the permission classifier now defaults to Sonnet 5 for external sessions, validated on the session's first request and pinned for the session
- Improved the bundled dataviz skill's chart color validation with perceptual OKLab color difference and recalibrated color-blindness thresholds
- Memory writes that leave a MEMORY.md index over its read limit now produce an explicit error instead of silent truncation
- Screen reader mode now announces permission mode changes aloud when cycling modes with Shift+Tab
- The agents footer hint now shows how many background agents are waiting on your input, with a brief color emphasis when the count changes
- Agent view: the session you pressed ← from stays visibly marked even after mouse hover or arrow keys move the selection
- Fable temporarily shows as unavailable in the advisor picker while a server-side issue causing Fable advisor failures is fixed