Skip to content

claude-code

Claude Code 2.1.288 brings back the prompt you Ctrl+C'd

Claude News

Hit Ctrl+C on a half-written prompt with screenshots pasted in, and in Claude Code 2.1.288 you can press Up on the empty prompt to get all of it back, images included. The release notes on GitHub also list a long run of fixes to resume, plugins and permissions, including a dangerous rm that could run without asking.

At a glance

  • The release adds /code-review --max-findings <n>|all, a re-authenticate prompt when an MCP server wants more OAuth scope during a tool call, and a prompt for dangerous rm inside bash -c scripts.
  • Several fixes come with hard numbers: LSP requests now time out after 60 seconds, unattended retries give up after three timeouts, and MCP calls with results over 16 MB stop running twice.
  • One fix has a cost. The first request in a fresh environment or after a model switch may now wait up to 1.5 seconds, so it can use the server's output limit and auto-compact window.

If you missed the earlier episode: according to Truefoundry, in December 2025 a user asked Claude Code to clean up packages in an old repository, and it generated rm -rf tests/ patches/ plan/ ~/. The shell expanded the trailing ~/ to the user's entire home directory. Truefoundry adds that Simon Willison flagged it on X and that the Hacker News thread drew 197 points and over 156 comments.

Pressing Up on an empty prompt restores a draft cleared with Ctrl+C

The headline change is small and concrete. Clear a prompt with Ctrl+C, then press Up while the prompt is empty, and the draft comes back with its pasted text and images. It works much like the shell history you already use, except it remembers the thing you just threw away.

/code-review gains --max-findings <n>|all to report more or fewer findings than the usual limit, and the choice sticks until you pass --max-findings default. If an MCP server asks for more OAuth scope during a tool call, you now get a prompt to re-authenticate.

The agents view adds Ctrl+F to find a session by name and Alt+↑/↓ to jump between groups, and Enter now opens the best-matching session instead of the top row. Both shortcuts, and rename, can be rebound in keybindings.json.

A dangerous rm inside bash -c ran with no prompt in bypassPermissions mode

A fix tracked as #96300 concerns a dangerous rm, such as one on / or the home directory, inside a bash -c or sh -c script. In bypassPermissions mode, or under a shell allow rule, that command ran without a prompt. In 2.1.288 it no longer slips through.

According to Codepointer's walkthrough of Claude Code internals, every tool call passes through a rule pipeline in which an inner function returns allow, deny or ask and an outer one settles the verdict against the runtime context. Deny rules are checked before the mode, so they win even in bypassPermissions mode.

Codepointer adds that paths such as .git/ and .bashrc still force a prompt even with --dangerously-skip-permissions. Each tool runs its own permission check, and Bash, the most complex case, uses AST-based injection detection.

Hooks that fail to match now block the tool call instead of being skipped

PreToolUse and PermissionRequest hooks used to be skipped when matching them failed or the tool's input could not be serialized to JSON. In those cases the call is now blocked. A BASHPID assignment whose value the shell would evaluate as arithmetic also triggers a prompt instead of passing silently.

One change goes the other way. Under sandbox auto-allow, sandboxed heredocs with an unquoted delimiter, such as python3 <<EOF, stop asking for approval on every run when the body holds only plain text and simple $VAR references.

According to Truefoundry, approval fatigue is the reason the --dangerously-skip-permissions flag exists at all: a 10-file refactor generates 30+ prompts, and most developers end up rubber-stamping them without reading a single one.

Resume gets four separate fixes, and timeouts stop killing turns

A mid-response API timeout used to fail the turn. Non-interactive sessions and subagents now continue from the partial response, and thinking-only responses are retried. Unattended sessions under CLAUDE_CODE_RETRY_WATCHDOG, which could retry for hours after a very long stream failed, now stream again and give up after three timeouts.

The four resume fixes: --resume keeps the files a compaction had just restored, the last response of a turn gets saved, the transcript loads in full when the session rewrites the file mid-load, and conversations started on 2.1.286 or earlier keep the model's earlier thinking. LSP requests now time out after 60 seconds (per-server requestTimeout).

The changelog says what changed but not how. It does not explain how the new rm check reads a nested script, whether wrappers other than bash -c and sh -c are covered, or how often the 1.5-second wait will happen in practice. In our view the trade is sensible: one pause of up to 1.5 seconds buys a first request that uses the server's limits instead of the built-in ones.

Where the purge alias and model pins stand

The release renames claude project purge to claude purge. The old name still works and prints a notice, and no date has been given for removing it. The client-side auto mode classifier now ignores an ANTHROPIC_DEFAULT_SONNET_MODEL pin naming Claude Sonnet 5.5 or Opus 5.5 and uses Claude Sonnet 5 instead, and the notes do not say whether that substitution will ever be lifted.

Related stories

  1. Claude Code ships mods, the same tool behind its /diff
  2. Claude Code 2.1.286 stops resume from losing your turns
  3. Claude Code writes the eval, grader included
  4. Without CLAUDE.md, Claude Code 2.1.277 reads AGENTS.md
  5. Claude Code tags gateway requests by class and agent
  6. Claude Code 2.1.269 grades plugins with a scored eval run

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.