Skip to content

claude-code

Claude Code 2.1.292 gives sub-agents their own effort dial

Claude News

If you hand work to sub-agents, Claude Code 2.1.292 lets you decide how hard each of them thinks. The Agent tool takes an effort parameter, and Claude runs the sub-agent at the level you ask for. The release notes on GitHub list this among more than 90 entries. Most of them are fixes, and one is marked as a security fix.

At a glance

  • Beyond sub-agent effort, the release lets claude plugin install add a missing marketplace under the usual policy checks and adds a variable for longer backoff on overloaded 529 retries.
  • Local stdio MCP servers negotiate protocol version 2026-07-28 by default on every install, Bedrock, Vertex and Foundry included, and MCP_PROTOCOL_NEGOTIATION=legacy opts out of the new behaviour.
  • The catch sits in the security fixes: PreToolUse hook approvals and auto mode skipped the permission prompt for file reads from network (UNC) paths, and the notes do not say since which version.

The Agent tool takes an effort level, and plugin installs can fetch their own marketplace

On paper the headline change is small. When the main session starts a sub-agent through the Agent tool, it can pass an effort parameter, and Claude runs that sub-agent at the effort level you asked for. The same release adds CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS, which sets a longer base delay for the backoff when an overloaded (529) request is retried.

Installing a plugin takes one step fewer. claude plugin install --marketplace <source> adds the marketplace if it is missing, under the same policy checks as claude plugin marketplace add, and then installs the plugin from it. A related fix stops plugin commands such as marketplace add and install from running on a first run before an organization's managed settings have loaded.

Mod authors get three new hooks into the engine. A prompt.autocomplete event adds rows to the prompt box's autocomplete list, and $.model.complete gains prompt caching. The agent.spawn hook now sees workflow agents, with their run and index, so a mod can refuse them. Agent names are capped at 256 characters, and a skill's or plugin file's name longer than that is ignored.

Local MCP servers move to protocol version 2026-07-28 by default

Local (stdio) MCP server connections negotiate protocol version 2026-07-28 by default on every install, including Bedrock, Vertex and Foundry. Setting MCP_PROTOCOL_NEGOTIATION=legacy opts out. A server that ignores the newer protocol check costs you one slow connect. After that, Claude Code remembers it for 7 days and connects the older way without the wait.

Two more MCP changes affect startup and stability. The first turn of claude -p and SDK sessions no longer waits for HTTP and SSE MCP servers to answer resources/list. An MCP tool with a name longer than 128 characters used to make every request fail. That tool is now left out, and an MCP error names it.

A read from a network path could skip the permission prompt

The one entry the changelog labels as security: PreToolUse hook approvals and auto mode bypassed the permission prompt for file reads from network (UNC) paths. On Windows, rm -rf on the 8.3 short name or another alternate spelling of the home folder or a drive was not treated as removing it. On macOS and Windows, a notebook or PDF read could return a file outside what was approved, through a link swapped in mid-read.

Sandboxed commands could read the staged file copies of /ultrareview uploads under ~/.claude/seed-admin. A tampered on-disk cache of server-managed settings could switch off or unseat the built-in policy plugin while the settings fetch failed. Sub-agent definitions with permissionMode: auto entered auto mode even when it was unavailable, whether it was disabled by settings, stopped by a circuit breaker or unsupported by the model. And <system-reminder> tags in a hook's output are escaped before they reach Claude.

PDF page lists and large @-mentions no longer fail silently

Several fixes replace silent failures with a message. Given a PDF pages value such as "6,9,15", the Read tool returned only the first entry with no error. It now returns an error saying to read each page or range separately. @-mentioned text files over 256KB were left out silently, and Claude is now told the file's size and to read it in portions. Grep and Glob reported no matches on unreadable paths, and Claude now retries once or tells you.

One-shot claude -p and Agent SDK runs stopped a background command 5 seconds after the final result, and one-shot claude -p runs also dropped scheduled wakeups. Both are now waited for. NO_PROXY is respected for Claude Code's own API requests, such as sign-in, policy, feedback and artifacts, when HTTPS_PROXY is set.

Plan mode is restored when you resume a session from the claude --resume picker or with /resume. The Artifact tool lets Claude list up to 200 published artifacts at once instead of 50. When a pull request edits CLAUDE.md, Code Review applies that file's version from the base branch.

What does a longer base delay do for 529 retries?

A 529 means the API is overloaded, so Claude Code retries with backoff: it waits, tries again, and waits longer each time. CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS sets the base delay, the first wait from which the later ones grow. It works like redialing a busy phone line. If you wait longer before the first redial, every pause after it gets longer too.

Prompt caching for mods works by marking a point in the request. In $.model.complete, prompt and system take blocks of text, and cache: true on a block caches the request up to that block. A mod that sends the same long instructions on every call can mark where they end and leave only the changing part after them uncached.

The notes do not say which effort levels the Agent tool accepts, what effort a sub-agent gets by default, or what the 529 base delay is before you change it. The UNC entry also gives no version range for the bypass. In our view, the PDF fix is the right design choice. A list like "6,9,15" now produces an error that tells Claude what to do, instead of one page that looks like a complete answer.

How long the legacy opt-out lasts

The changelog gives no date for retiring MCP_PROTOCOL_NEGOTIATION=legacy, so teams with older stdio servers can rely on it for now, but nothing promises it will stay. It is also worth watching what happens to a slow server once its 7-day memory runs out. The notes do not say whether the slow first connect comes back after that.

Related stories

  1. Claude Code 2.1.290 gives mod hooks the subagent's ID
  2. A Claude Code sideagent now flags what you might miss
  3. Claude Code 2.1.288 brings back the prompt you Ctrl+C'd
  4. Claude Code ships mods, the same tool behind its /diff
  5. Claude Code 2.1.286 stops resume from losing your turns
  6. Claude Code writes the eval, grader included

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.