2.1.265
Claude Code 2.1.265 - リリースノート
2026年9月8日
Claude Code
日本語サマリー
Claude Code 2.1.265 リリースノート要約
⚠️ セキュリティ修正
- プラグインパスにバックスラッシュが含まれる場合、macOS/Linux でシンボリックリンクの封じ込めチェックをバイパスできていた問題を修正
- Artifact ツールが他者が作成したアーティファクトを読む際、埋め込まれた指示をそのまま伝えるのではなく、信頼できないコンテンツとして扱い警告するように改善
破壊的変更に近い挙動変更
- managed settings で
forceLoginGatewayUrlが設定されたマシンは、起動時から Claude apps gateway セッションとして動作(残存する claude.ai ログインや API key は使用されない) - Claude apps gateway セッションは、gateway のリレー経由ではなく
OTEL_EXPORTER_OTLP_ENDPOINTで指定されたコレクターへ直接 OpenTelemetry をエクスポート(コレクター未指定の場合は従来通りリレー)
新機能
--plugin-dirがプラグインのフォルダを指定可能に(子フォルダ単位でロード、実行中の追加・削除も反映)- 非対話セッション(
-p、Agent SDK、クラウドセッション)でcdがターン間で保持されるように修正 - VS Code に非アクティブセッションの自動アーカイブ機能を追加(デフォルト 14 日)
- ツール結果のディスク保存に 1GB 上限を追加(切り詰め時にプレビューへ表示)
重要な修正
- フォアグラウンド起動の subagent を resume するとツール一覧とシステムプロンプトのプレフィックスが変わり、prompt-cache 再利用が壊れる問題を修正
- 前回プロセスがツール実行中に死亡した場合の resume で、最後のプロンプトが書き換えられず、中断されたツール呼び出しが「interrupted」として保持されるように修正
/model opusplan[1m]が "Model not found" で拒否される問題を修正httpとして設定された MCP サーバーが旧式 HTTP+SSE トランスポートのみの場合に接続できなかった問題を修正(SSE へのフォールバックを追加)- Windows: AppContainer / restricted-token サンドボックス内で Read、Write、Edit がすべてのファイルを拒否する問題を修正
その他の改善
--worktree起動が大きなリポジトリで高速化(git 2.32+ で並列チェックアウト)- 長いセッションの resume が高速化
/workflowsのエージェント詳細でツール呼び出しの状態(running / failed / done)やタスクリストを表示tmux内などで 2 キーのキーボードショートカットが 1 秒超で黙ってキャンセルされる問題を修正(3 秒待機し、タイムアウト時は通知を表示)
原文(Release Notes)
What's changed
- Added
user.emailanduser.groupsto the telemetry Claude Desktop and Cowork send through a Claude apps gateway, matching terminal sessions- Added support for pointing
--plugin-dirat a folder of plugins: each child folder with a manifest loads, and children added or removed while running are picked up- Added a 1 GB cap on tool results saved to disk; the in-conversation preview says when a saved file was truncated
- Fixed resuming a foreground-spawned subagent changing its tool list and system prompt prefix, which broke prompt-cache reuse for that agent
- Fixed agent teammates and resumed subagents moving SubagentStart hook context and preloaded skills out of the prompt prefix on later turns, which broke prompt-cache reuse
- Fixed resume after the previous process died while a tool was running: the last prompt is no longer rewritten, and the interrupted tool call is kept and marked interrupted
- Fixed
/model opusplan[1m]being rejected with "Model not found"- Fixed syntax-highlighted code in permission prompts and messages sometimes omitting a character after a Ruby
?, Erlang$, or Perl$sigil- Fixed the fullscreen transcript jumping by one row whenever the slash-command or @-file suggestion list opened or closed
- Fixed a plugin path containing a backslash bypassing the symlink containment check on macOS and Linux
- Fixed plugin directories whose names begin with two dots being wrongly refused as outside the plugin root
- Fixed VS Code and SDK sessions occasionally requiring re-login when a session was closed while refreshing its token
- Fixed Remote Control sessions sending the end-of-turn signal before the reply's last message, which could show a reply as finished in the Claude app before its last part arrived
- Fixed background (
--bg) sessions occasionally being retired mid-turn when a message arrived just before the idle timeout- Fixed Claude Code's own git status and diff probes running clean filters configured by a nested repository inside the working tree
- Fixed the advisor tool and its instructions being re-decided per request from the request's model; the decision is now made once and announced in the conversation when it changes
- Fixed artifact publish accepting connector tool names the connector doesn't expose; the publish is now refused when none of the declared tools exist, and warned when only some don't
- Fixed
/add-dir <subdirectory>refusing to load a subdirectory's agents when managed settings lock only skills to plugins, and promising agents when only agents are locked- Fixed two-key keyboard shortcuts cancelling silently when the second key arrived more than a second later, as happens inside tmux; they now wait 3 seconds and show a notice when they time out
- Fixed forked skills (
context: fork) not streaming their kickoff prompt and, with--forward-subagent-text, their text turns as progress events in stream-json- Fixed a plugin's default component folder that the OS cannot check, such as a symlink loop, being silently skipped; it is now reported in
/pluginwith the error code- Fixed the Claude apps gateway's OTLP telemetry relay pausing all forwarding to a collector for 30 seconds after it rejected a few payloads as malformed or too large
- Fixed
/pluginDiscover/Browse andclaude plugin list --json --availableshowing no description or display name for marketplace plugins whose metadata lives only in theirplugin.json- Fixed
/loginshowing "no gateway URL is configured" when re-run in a session that signed in to a Claude apps gateway set by managed settings- Fixed
/modelclaiming a model was "saved as your default" when the settings file couldn't be written; it now says the save failed and why- Fixed
/clearfrom Remote Control waiting on SessionStart hooks and on open terminal dialogs before completing- Fixed the
/configdialog changing height when switching between its tabs- Fixed resuming a workflow run after its container restarted; a resume whose run journal is missing now fails with a clear error instead of rerunning every agent
- Fixed the
claude-apiskill's error-code reference: model access failures return 404 and unavailable beta headers return 400, not 403- Fixed non-interactive sessions (
-pwith stream-json input, Agent SDK, cloud sessions) resetting the shell working directory at each new user message; acdnow persists across turns- Fixed MCP servers configured as
httpthat only speak the legacy HTTP+SSE transport never connecting; Claude Code now falls back to SSE as the MCP spec describes- Fixed some claude.ai connectors in cloud sessions showing as needing authentication even though they are connected in claude.ai (servers that answer an unsupported request with HTTP 401)
- Fixed remote sessions keeping their sandbox container alive while a connector approval or sign-in link waits for you
- Fixed resumed sessions showing long model-facing recovery instructions in "background task didn't finish" notices instead of a short status line
- Windows: Fixed Read, Write and Edit refusing every file ("symlink resolution changed after permission was checked") when running inside an AppContainer or restricted-token sandbox
- Improved
--worktreestartup on large repositories: the new worktree is now checked out in parallel (git 2.32+)- Improved
/workflowsagent detail: tool calls are marked running, failed or done, the subagent's task list is shown when it has one, and Enter unfolds the listed calls with their inputs and results- Improved slash commands typed mid-prompt: matches now show in a list (Tab opens it outside fullscreen) instead of a single suggestion, and a plugin skill is now found by its bare name
- Improved remote MCP servers that need sign-in: Claude Code no longer registers an OAuth client with them until you actually authenticate
- Improved the time to resume long sessions that read many files
- Improved the error shown when an image over the size limits cannot be decoded: it now names the cause and how to fix it instead of only citing the limit
- Improved the Artifact tool's read of an artifact someone else wrote: the summary now treats the page as untrusted content and flags embedded instructions rather than relaying them
- Updated the
.claudefolder permission option to say what it actually allows: editing files in the project's.claudefolder (or~/.claude) for the session- Changed machines with
forceLoginGatewayUrlin managed settings to be Claude apps gateway sessions from startup, likeforceLoginMethod: "gateway"; a leftover claude.ai login or API key is not used- Changed image processing to use the runtime's built-in image support; the CLI no longer extracts a native image module to the temp directory
- Changed plugin display metadata to prefer the marketplace entry over
plugin.jsonon the Installed tab andclaude plugin details, filling gaps fromplugin.json- Changed Claude apps gateway sessions to export OpenTelemetry directly to a collector the gateway's managed settings name in
OTEL_EXPORTER_OTLP_ENDPOINT, instead of through the gateway's relay; sessions without a named collector still use the relay- [VSCode] Added automatic archiving of sessions inactive for a set period (new "Archive inactive sessions" setting, default 14 days)
- [VSCode] Fixed the sidebar chat coming back blank after Reload Window or a restart when the conversation had been open for more than 10 minutes
- [VSCode] Fixed the timeline dot sitting below the text on the "Remote Control is active" message