Worktree isolation was leaking git commands into the main copy

Claude Code 2.1.222 closes two permission bypasses. The big one: sessions running in an isolated worktree, and their subagents, could execute destructive git commands in the main working directory. Isolation now applies to file edits and Bash across all session types.
The second bypass: PreToolUse hooks with auto-approve were skipping tool restrictions in background agent tasks such as summaries, context compaction, and renames.
Two smaller changes. The /usage report was overstating the MCP server share; it now counts only requests where those tools' results were actually used. And Remote Control autostart can no longer be enabled from repo settings, only through /config at the user level.
The ultraplan feature has been removed from Claude Code.
Related stories
- Claude Code 2.1.223 patches a Bash permission bypass
- Claude Code 2.1.221: permission bypass fixed, Focus view in VSCode, credential masking
- Claude Code 2.1.282 ignores telemetry set by project files
- Claude Code opens network hosts one command at a time
- Claude Code v2.1.214 closes a Bash permission bypass
- Claude Code v2.1.211: a flag to forward subagent text
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
