2.1.277
Claude Code 2.1.277 - リリースノート
2026年9月18日
Claude Code
日本語サマリー
Claude Code 2.1.277 リリースノート要約
破壊的変更・セキュリティ関連
- TaskOutput ツールを廃止(非推奨扱いから削除)。Claude は Read でバックグラウンドタスクの出力ファイルを読むようになり、
taskOutputMaxCharsとTASK_MAX_OUTPUT_LENGTHは無効化 - セキュリティ強化: subagent の結果が「subagent 出力」であることを示すヘッダー付きで届くよう変更され、subagent のテキストがセッション自身の指示になりすますのを防止。Bedrock / Vertex / Foundry 上の workflow スクリプトの
agent()プロンプトも同様にフレーミング - プロンプトインジェクション対策: プロンプト内の不可視 Unicode フォーマット文字・タグ文字を除去し、送信前にクリーニング済みプロンプトを確認表示
sandbox.excludedCommandsの glob が複合 Bash コマンド全体をサンドボックス除外にしていた問題を修正(全部分が一致する場合のみ除外)
新機能
- AGENTS.md サポート: CLAUDE.md が無いプロジェクトで AGENTS.md を代わりに読み込み。
/configの "Project instructions" で変更可能(Bedrock / Vertex / Foundry は未対応) CLAUDE_GATEWAY_PROXY_IS_EGRESS_BOUNDARY=1を追加し、egress がフォワードプロキシのみのゲートウェイで全リクエストのホスト名解決をプロキシに委譲- Claude apps gateway のアップストリームに
headers:マップを追加し、プロバイダ前方のプロキシへ静的ヘッダーを送信可能に - VSCode: パネルメニューに Sign out、
/tasksコマンド、Copy response ボタン、アーカイブされたセッションの "Unarchive all" などを追加
主な修正
claude -p/ Agent SDK セッションが内部エラー後に無結果でハングする問題を修正(エラー報告+終了コード 1)- 前ターンに空のテキストブロックがあると “text content blocks must be non-empty” で全リクエストが失敗する問題(
--resume後も含む)を修正 - 旧ビルド(IDE 拡張同梱 CLI など)が同一マシンで動作するとログアウトされる問題を修正
- Edit ツールがエスケープされたバックスラッシュ+
uXXXXを\uXXXXエスケープと誤解釈し、非 ASCII 文字の編集を誤る問題を修正 /mcpや/plugin manageオープン時のクラッシュ、~/.claude.jsonの不正なtheme値による起動クラッシュなど、複数のクラッシュを修正/clear後のセッション再開で SessionStart hook の出力時に最初のメッセージの一部が欠け、プロンプトキャッシュが完全にミスする問題を修正- ヘッドレスの
--resumeでコスト・使用量がゼロから始まる問題、レジューム後の添付の再レンダリングで拡張思考が失われキャッシュミスする問題を修正
その他の改善
- SDK・ヘッドレス (
-p) 使用時の初回ターンが CLAUDE.md のディレクトリ毎検索を待たないようになり、起動を高速化 claude -pで SDK / IDE 起動以外の場合、バックグラウンドの Haiku 自動タイトル生成リクエストを廃止- Fable が
/modelに常に表示され、組織設定で無効化されている場合のみグレーアウト - 危険な rm コマンドの権限プロンプトが対象コマンド名と
${VAR:?}ガードを提示し、ヘッドレス実行でも復旧可能に
原文(Release Notes)
What's changed
- Added AGENTS.md support: in a project with no CLAUDE.md, Claude Code reads AGENTS.md instead; change it under "Project instructions" in
/config(not yet on Bedrock, Vertex or Foundry)- Added
CLAUDE_GATEWAY_PROXY_IS_EGRESS_BOUNDARY=1for Claude apps gateways whose only egress is a forward proxy: every outbound request hands the proxy the hostname instead of resolving it locally- Added an optional
headers:map on Claude apps gateway upstreams, to send static headers to a proxy you run in front of a provider- Added a line saying a background task's update is waiting when it finishes while a panel such as
/tasksis open- Fixed
claude -pand Agent SDK sessions that could hang with no result after an internal error; they now report the error and exit with code 1- Fixed conversations failing every request with "text content blocks must be non-empty" when an earlier assistant turn held an empty text block beside other content, including after
--resume- Fixed being unexpectedly logged out when an older Claude Code build (for example an IDE extension's bundled CLI) runs on the same machine as the current one
- Fixed interactive start-up hanging or showing an error for
ANTHROPIC_API_KEYusers when~/.claude.jsonholds a malformedcustomApiKeyResponsesvalue- Fixed update checks erroring every 30 minutes, and
claude updatehanging when a minimum or maximum version is set, if a proxy returns an invalid version; a malformedminimumVersionis now ignored- Fixed
claude updateon winget- or apk-managed installs reporting "up to date" when the version lookup failed- Fixed
claude plugin installsometimes failing and breaking the installed copy when reinstalling a plugin version that a session or another program was using; an unchanged copy is now left alone- Fixed Grep and Glob reporting no matches when the search could not start because the system was out of processes, memory or file handles; they now return an error saying so
- Fixed the Write tool silently ending the turn as a declined permission when the target path is an existing directory; it now reports a clear error
- Fixed the Edit tool treating an escaped backslash followed by
uXXXXtext as a\uXXXXescape, which could make an edit of a non-ASCII character rewrite an escaped backslash sequence instead- Fixed the Edit tool reporting "Invalid regular expression: regular expression too large" instead of "String not found in file" when a very large edit containing non-ASCII text did not match the file
- Fixed a turn ending early with "Path contains null bytes" when a tool call's file path contained
\^@written as an escape sequence; escaped control characters now stay as literal text- Fixed background sessions (
claude --bg) exiting when a plugin's LSP server exited or closed its stdin- Fixed a crash ("Type error") when opening
/mcpor/plugin managewith a malformedclaudeAiMcpEverConnectedvalue in~/.claude.json- Fixed a crash at launch when
~/.claude.jsonholds a malformedthemevalue- Fixed a crash ("unrecoverable interface error") when the prompt held text containing terminal color codes, for example a prompt recalled from history or text loaded from the external editor
- Fixed a crash when resuming a session whose saved history holds an assistant message stored as a plain string
- Fixed sessions on slow or heavily loaded machines sometimes exiting with "Claude Code exited after an unrecoverable interface error" when the first spinner appeared
- Fixed a rare case where the screen could stop updating for the rest of the session after an internal rendering error
- Fixed a rare case on Windows where a turn could stop with an error such as "Out of memory" right after Claude replied, so that reply's tool calls never ran
- Fixed sessions continued after
/clear(restart,--continue,--resume) missing part of their first message when a SessionStart hook printed output, causing a full prompt-cache miss- Fixed messages from other agents (such as a subagent's SendMessage) that arrived mid-turn showing up below the "Ran N shell commands" row instead of where they arrived
- Fixed the "copied" notice not appearing after drag-selecting text in the fullscreen
/resumepicker and other panels that cover the prompt area- Fixed
$TMPDIRexpanding empty in Bash commands that run outside the sandbox while sandboxing is enabled- Fixed WebFetch and WebSearch in Cowork cloud sessions not telling Claude why a request was refused, such as a used-up fetch budget or an admin policy
- Fixed the Claude apps gateway's telemetry relay ignoring a collector hostname or domain listed in
NO_PROXYwhen a proxy is set- Fixed one malformed
strictKnownMarketplacesorblockedMarketplacesentry silently disabling the whole enterprise marketplace policy- Fixed failed auto-updates leaving large staged downloads behind in
~/.cache/claude/staging- Fixed
/pluginnot stripping terminal control characters from messages on the Installed tab, such as the error of a failed plugin update- Fixed
/plugin→ Installed and/skillscrashing when a skill or legacy command is named like a built-in Object property such asconstructorortoString- Fixed
/pluginclosing with no message when every install in a multi-select failed- Fixed uninstalled plugins reappearing as "failed to load" rows in
/pluginInstalled, and Remove not clearing such a row- Fixed plugins from the official marketplace being recorded without their commit in
installed_plugins.json, andinstalled_plugins.jsonkeeping the old commit after updating a pinned-commit plugin- Fixed plugin reload previews keeping every previewed copy of a plugin archive unpacked until exit, and overwriting the cached
--plugin-urlarchive a reload falls back to when its download fails- Fixed Remote Control session bookkeeping failing when
~/.claude.jsonholds a malformed placeholder record- Fixed the error after a revoked claude.ai login blaming an expired Anthropic profile; it now leads with
/login- Fixed typed or pasted text occasionally coming out scrambled in the
claude agentsdispatch input during key repeat or very fast input- Fixed a crash ("unrecoverable interface error") when resuming a session whose saved transcript contains a stop hook summary without a well-formed hook list
- Fixed Enter on a selected agent panel row doing nothing when
keybindings.jsonrebinds Enter in the Chat context, for example tochat:queueSubmit- Fixed PDF page reads on Windows failing when the working folder's path is long (about 120 characters or more)
- Fixed a headless resume (
claude -p --resume, the SDK, a VS Code extension window reload) starting the session's cost and usage totals at zero; headless sessions now save their totals at exit- Fixed project skills from the main repository not loading in
--worktreesessions when.claude/skillsis untracked- Fixed a
sandbox.excludedCommandsglob exempting an entire compound Bash command from the sandbox when only one part matched; every part must now match- Fixed resumed subagents and teammates re-rendering the MCP tool definitions they had loaded, which broke prompt caching for that agent
- Fixed rate-limited artifact publishes telling Claude to stop retrying; Claude is now told nothing was published and when to send the same publish again
- Fixed attachments recorded earlier in a conversation being re-rendered after a resume or relaunch, which dropped extended thinking and missed the prompt cache
- Fixed Console sign-in showing only "Request failed with status code 400" when the server refuses to create an API key; it now shows the server's message
- Fixed messages typed while Claude is still working sometimes being ignored by the model
- Improved session start-up for SDK and headless (
-p) use: the first turn no longer waits on the per-directory CLAUDE.md lookup- Improved the Claude apps gateway's loopback error messages to name
CLAUDE_GATEWAY_ALLOW_LOOPBACK- Improved
/pluginInstalled: an MCP server listed apart from its plugin now shows which plugin it belongs to- Improved
claude plugin installon an already-installed plugin: it now says when the marketplace offers a newer version and names theclaude plugin updatecommand- Improved the startup notice overflow line under the logo: it now reads "N more notices hidden" instead of "+N more · /status"
- Improved prompt handling: invisible Unicode formatting and tag characters in a prompt are removed and the cleaned prompt is shown for review before it is sent
- Improved
/ultrareviewwhen there's nothing to review: messages say which case you're in, offer a command that reviews your latest commit, and a new repository's first commit is reviewed in full- Improved artifact link handling so Claude reads claude.ai artifact links with the Artifact tool instead of WebFetch when that tool is available
- Improved the dangerous-rm permission prompt to name the flagged rm command and suggest a
${VAR:?}guard, so headless runs can recover- Improved the Artifact tool's permission prompts: shorter sentences, pages and artifacts named by title or file name, and links listed after the text
- Changed Fable to always appear in
/modelon the Anthropic API; it is greyed out only when your organization's settings disable it- Changed the Bash sandbox instructions on Bedrock, Vertex and Foundry to the first-party wording, which frames the sandbox as the boundary of what the task was given
- Changed
/ultrareviewin non-interactive sessions to refuse when the repository has no base branch or shared history- Changed subagent results to reach the main agent under a header marking them as subagent output, with the result indented, so text in a subagent's result cannot pass as the session's own instructions
- Changed workflow scripts' computed
agent()prompts on Bedrock, Vertex and Foundry to reach the subagent framed as script-authored text, so the safety classifier does not read them as the user- Removed the background Haiku auto-title request from
claude -pruns launched outside an SDK or IDE- Removed the deprecated TaskOutput tool; Claude reads a background task's output file with Read instead, and the
taskOutputMaxCharssetting andTASK_MAX_OUTPUT_LENGTHno longer have any effect- [VSCode] Added a Sign out row to the panel menu, with
/logoutin the typed command menu- [VSCode] Added background shells and other running tasks to the agent map, each with a Stop, and a typed
/tasksthat opens it- [VSCode] Added a Copy response button on responses and a typed
/copy- [VSCode] Added a one-time notice when inactive sessions are archived automatically, and an "Unarchive all" action on the Archived sessions group
- [VSCode] Added the session's cost and token usage to the Account & usage dialog and the session manager where plan limits do not apply (Vertex, Bedrock, Foundry, API key)
- [VSCode] Fixed the "General config" menu row showing
/configusage text instead of opening settings, and made typed/mcp,/hooks,/memory,/rewindand similar commands open their dialogs- [VSCode] Fixed the effort slider's level not persisting into later sessions on a model that already had a level saved with
/effort- [VSCode] Fixed Auto missing from the mode picker for conversations opened in an already-used panel when the saved model setting is a differently-cased alias such as "Sonnet"
- [VSCode] Fixed
/fastnot saving fast mode as the default, so it was lost when the extension relaunched Claude Code- [Claude Code on the web] Added Personal and Organization sections to the environment picker on Team and Enterprise plans, and admins can now share a personal environment with the organization
- [Claude Code on the web] Changed organization environments to open as a read-only summary from the Code tab on Team and Enterprise plans, with editing under Admin settings → Cloud environments
- [Claude Code on the web] Fixed a cloud environment saved with Custom network access and no domains silently reverting to Trusted; the dialog now asks for at least one domain
- [Claude Code on the web] Changed the admin Claude Code setting labeled "Web" to "Cloud sessions" and removed the redundant read-only Mobile row beneath it
- [Claude Tag] Fixed routines created in a Slack channel on an Enterprise Grid org-wide install failing to read other public channels in their workspace when they ran
- [Claude Tag] Fixed the "Learn more" links on credential presets in Claude Tag access bundles to open each vendor's credential-setup page instead of a generic API reference
- [Claude Tag] Changed the Pylon credential preset in Claude Tag access bundles so admins can point it at Pylon's EU host
- [Claude Tag] Fixed Google Cloud credential forms in Claude Tag access bundles: a refused key file now says why, the website and scopes stay locked, and a rejected rotation keeps the pasted key
- [Claude Tag] Fixed the network events log in Claude Tag admin settings showing no response status for requests through connections that use AWS signing, client certificates or a custom CA