Anthropic released Claude Code 2.1.287 on October 1 at 18:00 UTC. It introduces Claude Mods, described as a way for plugins to change deeper behavior, and an optional companion called “You should know” that flags things the user or main agent may miss. The companion is limited to first-party sessions with telemetry enabled. Official release notes.
The same release includes permission and recovery changes. For teams running unattended or long-lived coding work, those details deserve a rollout check alongside the new feature. A plugin that adds another agent changes the work you need to observe; a recovered session still needs to be matched to the repository state it resumes.
This is an analysis of the published changes and a proposed verification plan. We have not run these two releases against a matched test suite, and we do not claim a measured improvement in coding quality, speed or cost.
Separate the new feature from the fixes
The October 1 notes report fixes for a dangerous shell-removal command losing an always-ask safeguard when combined with particular output redirects, and an organization’s per-tool permission ceiling being dropped for an MCP tool named __proto__. They also add prompt_text, a copy of the prompt in an OpenTelemetry event, which needs the same masking treatment as the existing prompt field. These are vendor-reported fixes, not evidence of a complete security audit. 2.1.287 changes.
Review these changes with the person who owns your managed settings and observability pipeline. An application update, a plugin update and a policy update are different variables. Record them separately so a change in behavior can be traced to the right one.
Keep the optional companion disabled for an initial baseline if you want to compare core behavior. Then evaluate it in a separate, approved cohort. Define what counts as a useful warning: a real missed requirement, a reproducible problem or a concrete missing check. Count interruptions and incorrect warnings as well. That is a proposed evaluation method; the release notes provide no independent warning-quality score.
Check your actual version and update channel
Start with claude --version on the machines that matter, including remote workers. A local terminal and an automation host can run different builds. Record the installation method and channel rather than assuming everyone received the October 1 release.
Anthropic’s setup documentation says native installations update automatically. Homebrew and WinGet installations require their package-manager updates. It also distinguishes Homebrew’s stable cask from the latest cask; stable typically trails latest by about a week and skips releases with major regressions.
Choose the update route appropriate to that installation. The CLI reference documents claude update and installing a specific native version. Use your organization’s existing release policy for deployment and rollback. Preserve the previous version, configuration and work state before changing a worker that has unfinished tasks.
A version number is only the start of the receipt. Include the selected model, permission mode, enabled plugins, MCP servers and relevant managed settings. Without that context, two people saying they tested “the new Claude Code” may have tested different systems.
Reconcile the September 30 recovery and spend changes
Version 2.1.286, published September 30 at 19:10 UTC, reported a fix for resumed or continued sessions losing turns after a crashed batch of parallel tool calls. It also corrected the Claude apps gateway’s spend meter for one-hour cache writes and streamed turns containing server-side tools. September 30 release.
Those earlier fixes help explain why an upgrade check should include both continuity and accounting. They do not establish that your historical bill was wrong or that the update reduces the price of a model. If your displayed estimate changes, preserve the token categories and rates used on each side of the comparison before drawing a conclusion.
Anthropic’s cost guide says the Session block in /usage is an API cost estimate. It computes from token counts and list prices unless managed pricing is configured. The Claude Console is the authoritative billing reference for direct API use. For Pro and Max subscribers, the session dollar estimate is not their subscription bill.
For a team pilot, keep a row per attempt: task identifier, resolved model, token categories, displayed estimate, billing route and accepted result. Include retries and failed attempts. Do not divide spending only by the number of requests that happened to succeed.
Use harmless fixtures for permission checks
A permission regression should be tested with disposable, non-sensitive fixtures under a documented boundary. Do not reproduce a dangerous deletion against a real home directory just because the release notes mention it. Ask the administrator to check the relevant policy path using the team’s established safe validation process.
For prompt telemetry, inspect the schema and redaction rules before collecting real project prompts. Check both field names in a synthetic event. A rule that masks one spelling but leaves its copy visible would create an avoidable discrepancy between what the team intended to collect and what it retained.
Treat plugin enablement as a separate approval in your own deployment process. Record the plugin version and permissions, who enabled it and how to disable it. The release’s brief description of Mods does not establish that every third-party plugin is trustworthy or compatible with your environment.
Keep a small, inspectable rollout record
Choose one representative repository task with explicit acceptance criteria and no production credentials. Save the starting revision and configuration. After an authorized test, keep the diff, checks, transcript and cost observation together.
| Proposed check | What to compare | What should block a wider rollout |
|---|---|---|
| Resume an interrupted task | Transcript, repository diff and remaining requirements | Missing work history or repeated side effects |
| Inspect a permission boundary | Expected policy and harmless fixture result | An action proceeds beyond the configured allowance |
| Review prompt telemetry | Synthetic prompt fields and exported event | A copied field bypasses the intended masking |
| Enable the optional companion separately | Useful findings, false warnings and interruptions | Added activity without enough useful findings for the developer |
These are proposed acceptance checks, not results from this desk. For broader product selection, our Codex versus Claude Code comparison distinguishes tested tasks from product claims. For this update, keep the rollout decision attached to the exact version, settings and retained checks your team reviewed.
The Kingy Brief
Get future Kingy Brief editions.
Source-checked AI changes, original tests and one practical thing to try.
Free · Choose your subjects · Double opt-in · Unsubscribe anytime
Regular sending is paused; no restart date is set.
