Digest / August 10, 2026
Claude Code Issues Digest — August 10, 2026
253 new issues filed ·
149 resolved in anthropics/claude-code (UTC day).
New issues (253)
- FAbl5 switching [Bug] Unexpected model switching from Claude 3.5 Sonnet
- [BUG] Daemon bg/spare sessions leave title-only .jsonl stubs in the resume picker; resuming errors, then starts a blank session that re-submits the last prompt
- [Bug] Safety flag incorrectly triggers on defensive security audits of own codebase
- Claude Code, although openrouter api models were also discussing ectoctopic pregnancy
- [BUG] Session branch created even when "main" is explicitly selected as base branch (Claude Code desktop )
- Background task notifications cancel pending permission requests with a message that impersonates the user
- asking something simiple
- Auto mode: safety classifier blocks read-only MCP tools when the conversation model is unavailable
- Cross-session messaging: silent socket-bind failure when multiple sessions start in the same second
- Claude Desktop (macOS): auto-update relaunches the app and silently kills live session hosts — no way to disable it
- Fable 5 safeguards flag defensive security audit output (false positive)
- [Bug] Session unexpectedly downgrading to Claude Opus 4.8 from requested model Fable 5
- Subagent effort level is unobservable: cannot tell whether frontmatter `effort:` applies to background-dispatched subagents
- [Bug] Claude forgets outstanding to-do list items after multi-turn compactions
- [BUG] SSHFS read/write issue
- Feature request: Option to disable autocopy on text selection
- Desktop: "Toggle pinned summary" header control missing in some sessions
- security-guidance: layer 3 agentic commit review is default-on, unbudgeted, and its token usage is computed then discarded
- [FEATURE] Token-burn circuit breaker: runtime-enforced spend caps with per-source attribution (hooks, plugins, subagents), not just warnings
- [Bug] API errors triggered by specific file content causing persistent connection issues across sessions
- [BUG] Claude Desktop (Windows MSIX): GPU process repeatedly crashes with exitCode 101457950 (0x60C201E), killing the app and stranding it behind a stale single-instance lock
- [Bug] Anthropic API Error: Insufficient Permissions for Project Access
- [BUG] False positive content filter blocks standard e-commerce geoblocking implementation (state-level sales compliance)
- 【@@📞📞📞𝐎𝐟𝐟𝐢𝐜𝐢𝐚𝐥🧲Przewodnik po LOT @📞📞📞POL@SKA! 𝐓𝐞𝐥𝐞𝐟𝐨𝐧】 🧲Jak skontaktować się z centrum obsługi LOT?📞📞📞
- [BUG] SSE stream to /v1/code/sessions/.../worker/events/stream closes immediately after connect — ECONNRESET banner, 2 machines / 2 networks
- Allow custom slash commands to invoke other slash commands (e.g. /clear, /compact)
- [BUG] PreToolUse hooks silently do not fire for one working directory while permissions.deny from the same settings.json does
- [BUG] Desktop session list: untitled sessions are titled from the raw first prompt with no disambiguation — automated runs collapse into dozens of identical rows
- [BUG] German-language Claude Code corrupts canonical technical terminology (Gate→Zaun, Policy→Politik, Root→Wurzel), causing semantic and persistent-memory drift
- [BUG] Claude Code a planté
- [Bug][cyber] Safeguards trigger on local storage breakdown UI and redundancy coding (req_011CdtVjZMUpdEfEVKicVPec)
- Desktop: local session's remote-control bridge is never re-registered after app restart — session permanently invisible/stale on mobile and web
- [BUG] Text output duplicated when tool calls are mixed in the same response
- Desktop app: context indicator does not report the current chat after switching chats or before the first message
- [Bug] Fable model unusable for coding tasks
- [BUG] Hiding skills doesn't reduce total context: tokens removed from the Skills row reappear in System tools (exact 1:1, 3/3 configs)
- [Triage] Bug auto-closed as duplicate of an issue that was then auto-closed as NOT_PLANNED; both locked, leaving no open tracker
- [Bug] Terminal rendering broken with Bangla language input
- [BUG] Remote (Streamable HTTP) MCP form elicitation never reaches the client: no dialog, no `Elicitation` hook, server times out at -32001
- [BUG] Text block streamed between two thinking blocks is never written to the session JSONL (silent loss of user-facing replies; 3,738 across two machines since v2.1.170)
- [Bug][cyber] False positive when configuring application disguise UI and launcher aliases (req_011Cdta2YM9Vdb8wengGyaXd)
- default TUI: copy-on-select toast never renders
- [Bug] Rapid, unexplained usage limit consumption during normal usage
- Bash tool: unquoted env preamble breaks every command when an env var value contains newlines
- Agent tool's isolation:'worktree' binds the worktree's base repo to the caller's Bash cwd at dispatch time, not the target repo
- [Bug] Cyberverified user incorrectly flagged as unauthorized
- [Bug] Claude Code force-pushed open PR branch without explicit destructive operation consent
- git-subdir plugin sources fail on native Windows build - "git ... not on PATH" thrown without ever invoking git
- LŨ CHÓ MÁ ANTRHOPIC ĐẠO ĐỨC GIẢ, LỪA DỐI , DỐI TRÁ, LỪA GẠT
- [Feature Request] Add configurable paste collapsing thresholds or disable toggle
- [BUG] Sandbox proxy blocks branch deletion (git push --delete and DELETE /git/refs) while allowing force-push to the default branch
- [BUG] /rewind to before the first user prompt hydrates a degraded harness: SessionStart hook output replayed stale (not re-fired), skills listing dropped entirely
- [BUG] Sandbox proxy blocks branch deletion (git push --delete and DELETE /git/refs) while allowing force-push to the default branch
- [BUG] Bash tool LD_PRELOAD recursion can abort Claude Code session instead of returning a failed tool_result
- Streaming `/v1/messages` resets with ECONNRESET after the first chunk on Windows — system Node & undici stream fine, only Claude Code's bundled client fails
- [BUG/MODEL] Model told incorrectly that all bash commands are blocked
- [Bug] Overly aggressive safety filters blocking legitimate development files
- [BUG] Release notes never readable: startup banner overwritten instantly (regression of #51569), and one global lastReleaseNotesSeen is consumed by concurrent sessions
- [BUG]
- [FEATURE] Desktop App: Add the ability to share a private link privately
- [BUG] Skill commands are autocompleted and highlighted mid-sentence, but silently do nothing
- Default 30-day cleanupPeriodDays silently hard-deleted ~950 session transcripts (no warning, no trash) — please add safeguards
- [FEATURE] Let a Claude Code session deliver files and messages back into Dispatch
- Feature request: switch sessions in `claude agents` with Alt+number shortcuts
- [Bug] Model ignores global CLAUDE.md rules and reverts to project jargon in same session
- [Bug] FleetView TUI render loop frozen while attached to background fleet session
- [BUG] Suspicious injected instructions repeatedly appended to my own outgoing messages (Code tab)
- [Bug] Agent generates security vulnerability details in public issue reports
- [BUG] Stats → Models: bullet colors in the model breakdown list don't match the chart legend
- Scheduled tasks stop executing fleet-wide — nextRunAt advances while lastRunAt freezes silently (~44h, restart does not fix)
- [Bug] Misleading "Executable not found in $PATH" when a hook targets a Windows App Execution Alias (pwsh.exe, python.exe)
- [Bug] /add-dir does not strip surrounding quotes from path argument
- [Feature] Rules-governance diagnostics for CLAUDE.md / .claude/rules: instruction-budget warnings, duplication & conflict detection
- [BUG] Claude Code on the web: GitHub App has read-only access even though the same account has full write access from local Claude Code
- PreToolUse hooks do not fire on MCP tool calls from settings.json on Windows (PostToolUse does) — contradicts docs; #74203's Linux control test reports the opposite
- [Bug] Claude Desktop MSIX leaks kernel non-paged pool via NTFS CCB allocations (~2.2 GB/hour)
- [BUG] Desktop SSH remote: ~2s handshake timeout is unreachable at 250ms RTT — 139 session drops in one day
- [Bug] Claude Code unexpectedly deletes source files
- Auto-compaction INCREASES real on-wire context when preTokens diverges (up to 6.34x) and compaction fires below the rebuild floor — 133 net-negative events across 5,180 boundaries, worst +167,519 tokens, 12.9% of subagent compactions affected
- Desktop app: active session auto-archives repeatedly right after context compaction/continuation (3+ times in one day, no opt-out)
- [Bug] Tool call arguments incorrectly receive pasted content during paste operation
- [BUG]
- `AskUserQuestion` rejects valid-looking input with an opaque `could not be parsed as JSON` error
- Read-state is lost across auto-compaction → `File has not been read yet` on files already read
- Autocompact-thrashing warning blames "a file or tool output" when the refill came from re-injected project instructions
- A PreToolUse policy *deny* is surfaced to the model as a "hook error"
- Permission classifier blocks read-only operations the user explicitly pre-approved, and does so non-deterministically
- Compound bash command: one flagged segment forces approval for the whole command
- Hooks that need live session state only receive the transcript
- Active model can change mid-session after a resume without a visible signal
- [Bug] Unauthorized commits/pushes occurring despite permission restrictions enabled
- Self-directed adversarial review loops have no severity floor or spend ceiling — one ~700-line PR consumed two Max 20 accounts in days
- Session starts without binding its cross-session peer socket — registered but unreachable by SendMessage; silent failure, restart fixes
- Bug: Local MCP server not used by chat despite being enabled
- Auto-compaction fails and ends the session on third-party models after the new unknown-model window enforcement
- /insights counts subagent sessions as the user's own, inverting the conclusion
- [BUG] Windows Cowork workspace fails to start — CreateVirtualDisk 0xC03A0014 system-wide, sessiondata.vhdx never created
- [Feature Request] Add non-MoE model option for agentic reasoning tasks
- SendMessage returns success:true before the inbound decision; held/expired notice only arrives ~5min later (dialogExpiry)
- [Bug] Anthropic API Error: Request flagged without clear reason
- [BUG] VS Code chat: scrollbar stops short of assistant response after long pasted content, in both sidebar and full editor tab
- [Bug] Session termination triggered by profanity or aggressive language in prompts
- [Bug] Degraded Performance from Opus 5
- Long responses corrupt terminal scrollback — earlier output overwritten mid-stream (iTerm2)
- Desktop app "Total Tokens" stat is a truncated ~6-week window, not lifetime — mismatches CLI's own Stats screen on same machine
- [BUG] /rewind removes stashed messages
- Manual permission mode: file edits via Bash (python/sed) bypass per-edit diff review
- [Bug] Fable 5 safeguards blocking non-technical disagreement statements in security conversations
- Extended thinking / internal reasoning leaks as visible chat text (session-persistent, survives app restart)
- [FEATURE] Desktop: side-by-side (split) mode in the diff viewer, alongside the current inline view
- /code-review orchestrator stalls ~1h: subagent results misrouted to a different local session, parent never woken
- Fullscreen TUI copies never reach the RDP/AVD client clipboard: spawned Set-Clipboard helper exits before the AVD clipboard broker samples the update
- [BUG] Claude in Chrome file_upload: eligible files fail with -32602 "paths received undefined" in interactive Cowork sessions (Windows) — related to #84880 / #85107 / #63334
- Desktop app: Ctrl+F page search doesn't match Japanese text (only romaji/ASCII)
- Recap line should always include the repo name for multi-repo / background sessions
- [BUG] Inline images don't render in the VS Code extension sidebar (Remote-WSL): affects both `Read` and `SendUserFile`, plus a separate turn-injection bug in `Read`
- Desktop app GPU process renders continuously while backgrounded with a Claude Code remote session open (~60-90% system GPU)
- [BUG]
- [BUG] iOS: session re-enters plan mode after worker restart, causing an unbounded plan-approval loop that consumes usage unattended
- [Bug] Add support for testing model performance with/without context notes
- [BUG] .mcp.json at a Windows drive root is never discovered — absent from claude mcp list, no warning
- [BUG] API Error
- [FEATURE] Cowork: show full folder path (not just basename) for connected context folders in the Context panel
- [BUG] claude-code opens a new Terminal.app window on every session start, independent of terminal emulator
- Fable5 safeguards tripped while working on Yocto/Kernel/Kleaf
- code-review subagent generated deceptively-labeled rm -rf ("no-op placeholder") that passed human permission review and deleted the repo
- [Bug] Tool edits create/delete files without permission. Crap tool useless
- [Bug] Tool edits create/delete files without user confirmation LAWSUITS FILED YOU WILL BE SERVED IN UPCOMING WEEKS.
- [Security regression] Revoked Claude Code tokens still appear to consume Max usage after full logout
- Background-task completion notification enqueued but never delivered; subagents never re-invoked despite 'You will be notified' ack
- [Bug] Fable rejects authorized security evaluation tasks despite CVP approval
- [FEATURE] Cowork: make the project 'Edit instructions' dialog larger / resizable (current textarea is too small for real instructions)
- [Bug] Claude Code generates verbatim paper sections instead of analytical guidance
- [Bug] Model switch from Opus to Fable causes workflow interruption
- [BUG]"Connection closed mid-response" errors on tool calls with large output (~40+ lines), reproducible across terminal/network/install — not fixed by clock resyn
- [BUG] Windows MSIX: clicking an external link in the chat transcript crashes the app (GPU exit 0x060C201E) and forces an MSIX repair cycle - expected: open in default browser
- [Bug] Anthropic API Error: Request flagged by safety filters on benign prompts
- [Bug] Concurrent mobile Claude Code session corrupts text/document content in desktop claude.ai session
- [BUG] Desktop app: starting a session on a branch held by a linked worktree runs `git switch` in the main repo and fails (code 128) — even when the worktree folder itself is selected
- Long sessions: pre-existing CLAUDE.md rules lose to newly written ones, and the agent keeps adding more
- /model mid-session: served model changes but the agent's stated identity does not, and the agent cannot query it
- [BUG] VS Code extension: chat input box expands after pasting a code block and won't shrink back down
- Stop-hook block cap: document it, signal the override to hooks, and bless a pattern for deliberate long-running loops
- AI session titler overwrites user-set custom titles in long sessions (64 KB head/tail guard blind spot)
- [Bug] Anthropic API Error: Inappropriate Safety Filter Triggering on Non-Security Content
- Artifact cannot be shared publicly: "This version can't be shared publicly" persists across republishes (Max plan)
- 音声入力(マイク)ボタンが反応しない (Windows / VSCode拡張機能)
- Thai: Backspace deletes the whole syllable instead of one combining mark
- claude-in-chrome extension never connects despite being installed, enabled, and Chrome running
- automodeが実質意味がないものとなっている
- [FEATURE] Surface skill metadata frontmatter on skill_activated/plugin_loaded OTel events
- [BUG] Cowork option is misisng in existing chat and only appear when open new chat
- Portable Experience Memory Across Claude Sessions and Agents
- Feature request: native "open browser panel" action that doesn't require a model turn
- [Bug] Safeguard validation logic produces inconsistent results
- Docs say every desktop "+ New session" gets its own worktree; on 2.1.222 (Windows) it runs in the main checkout with no worktree created
- [Bug] Unclear - Linux Kernel/USB Firmware Development Context Mismatch
- [Bug] Incorrect reasoning about RDS dynamic parameter apply timing and sequencing requirements
- [BUG] MCP OAuth client ignores WWW-Authenticate resource_metadata URL; falls back to bare origin, breaking discovery under any non-root context path
- [Bug] Cyber-safeguard classifier false positives blocking CVP-approved penetration testing
- [BUG] Desktop app update silently wiped the internal scheduled-tasks registry (scheduledTasks: []) — all scheduled tasks died at once, with zero user notification
- [Bug] Anthropic API Error: Opus 4.8 Safeguards Blocking Authorized Messages
- Remote SSH: desktop app parks on "Reconnecting" for hours after a successful reconnect, and never retries
- User-role messages appear in context that were never submitted by the user (after resume)
- [Bug] Agent making assumptions without clarifying intent in review mode
- Collapsed transcript labels a Bash file write (`cat >>`) as "Read 1 file"
- [BUG] Illegal instruction crash on CPU below SSE4.2/POPCNT baseline (not just AVX)
- You've hit your session limit · resets 3pm (America/Bogota)
- Fullscreen TUI: assistant text dropped in turn continuations after AskUserQuestion answers
- [Bug] Safeguard Warning Incorrectly Triggered on Standard Backend Tasks
- [Bug] Sleep inhibitor rotation creates gap allowing system sleep during active tasks
- [BUG] Cowork sandbox: disk exhaustion is silent, and model-authored tests leak temp dirs at scale
- [BUG] Cowork device bridge: git add silently stages nothing in a connected folder (mount denies unlink)
- [BUG] Cowork device bridge: iCloud-evicted files list normally but are unreadable, with no way to materialise
- Auto-generated session titles render in Russian for Ukrainian-language sessions
- Remote session UI: plan-mode plan file chip fails to open ("file is on the machine running this remote session") because it lives outside the working directory
- [BUG] A PreToolUse hook can permanently deadlock a Cowork session with no in-session recovery, and a new chat reuses the wedged container
- Desktop app: folder assigned when creating a new session becomes an additional working directory — session's primary project silently stays the previous one
- [BUG] /tui reports the previous renderer on the first call after a switch
- Feedback: managed agents need permission-gated egress + a quarantine primitive for untrusted content (user: agent 'kneecapped' by hard egress blocks)
- [Bug] Agent fails to follow multi-step instructions and acknowledge plan deviations systematically
- macOS: recurring TCC permission dialogs labeled with a version number; grants voided by every auto-update
- [BUG] Plan file intermittently reported as non-existent while composing inline comments; unsaved comment text is lost
- Auto mode silently denies tool actions; denials never surface to the user - rename it or add a user-facing allow prompt
- /insights command ignores ANTHROPIC_MODEL env var, hardcodes claude-opus-5
- [FEATURE] Remove or make the Max plan five-hour hard stop configurable
- Read tool returns project-specific auto-memory content when global memory path is specified
- CLAUDE_CODE_SUBAGENT_MODEL silently discards explicit per-call subagent model since v2.1.223; documented warning never fires; subagent metadata records requested (not effective) model
- [BUG][A11y] macOS desktop app: sidebar conversation list, scheduled tasks and transcript are absent from the accessibility tree (containers present, zero children)
- [Bug] Goal execution loops indefinitely after completion with Opus 5
- Project identity resolved inconsistently: memory and /resume key on git repo root, transcripts key on cwd
- Model executed a full multi-file build in response to a question-phrased message (consent vs. reversibility gating)
- [BUG] Two concurrent sessions share ~/.claude — the Write tool silently overwrites another session's memory and rule files
- VSCode extension: `claudeCode.preferredLocation` silently overwrites an explicitly-set user preference
- [BUG] cowork-virtualization-bug-report
- [BUG] VSCode extension keeps crashing (6x today)
- CLAUDE.md (user-level, ~/.claude/CLAUDE.md) intermittently not loaded in new sessions (claude-desktop)
- [Bug] Anthropic API Error: Unspecified
- Typed input queued mid-turn is silently dropped at turn end (end_turn, no Escape involved) -- interactive TUI
- /security-review over an empty diff returns a clean report instead of "nothing to review"
- [Bug] File system path resolution fails for existing directories
- PreToolUse hooks cannot tell whether a human approved the call
- Hook-ask permission prompts default to Yes; a stray Enter publishes
- Hook-supplied permissionDecisionReason renders as one alarming block
- [ERROR] Error streaming, falling back to non-streaming mode: Connection error.
- [Bug] Excessive file searching in implementation mode despite clear plan context
- [Bug] Inconsistent safety policy enforcement causing mid-task failures
- [Bug] False positive policy warnings on local Polish-language JSON training files
- settings.json in an ancestor directory is silently ignored — hooks and permissions.deny never load, with no warning
- [BUG] Cross-session messaging has no account-level off switch — local-only controls can't contain sandboxed /auto or --dangerously-skip-permissions agents
- [Bug] Subagents killed by stall watchdog during active token generation
- [BUG] Paste/drag-and-drop of images into chat input fails silently (VS Code extension)
- Model asserted third-party delivery worked from sender-side evidence; false conclusion persisted through memory across sessions (11-day production outage)
- [Bug] Network interruptions can lead to false positive OAuth token expiration errors and a degraded application state
- [BUG] VS Code extension: ECONNRESET/ECONNREFUSED while bundled binary works when launched directly (2.1.226)
- [FEATURE] Expose remaining session/container lifespan + advance-shutdown warning so long-running sessions can checkpoint and hand off
- [FEATURE] Desktop app: prompt stash (Ctrl+S) parity with TUI
- [BUG]
- [BUG] Desktop (Windows/MS Store): local stdio MCP server from an uploaded plugin stuck "Not connected" — Install button just opens the public Connector Directory
- VS Code extension 2.1.226: worktree sessions unfindable in history search after reboot (+2 related)
- "Server disconnected" banner shown for routine idle/sleep MCP disconnects even when reconnection succeeds
- Claude Desktop: prompt-input dialog never calls completion/complete, ignores required:false, and caches prompt definitions for the whole session
- [Feature Request] Improve sandbox security guidance for Python script execution environments
- [BUG] /code-review ultra (ultrareview) fails with "GitHub repository access check failed" — GitHub App installation step never completes
- [BUG] Right-click paste duplicates text in Claude Code TUI on VS Code integrated terminal (Ubuntu/Wayland) — not reproducible in plain bash in same terminal
- [BUG] /plugin menu: install failure error flashes briefly and menu exits — error text unreadable, only recoverable via non-interactive CLI
- PostToolUse: malformed updatedToolOutput passes validation and throws 'e.reduce is not a function' instead of falling back to original output
- Voice dictation: persistent "No audio detected" in agent overview and resumed sessions — tap toggle double-fires (start + stop within ~330 ms); fresh session works fine
- Opus 5: model fabricates requirements and acts without permission while self-verifying a different axis
- [Bug] Anthropic API Error: Recurring request failures
- claude mcp login fails with 'unable to get local issuer certificate' against standard, non-intercepted certs
- [FEATURE] Serif font option for Claude Code desktop interface
- [Bug] Claude generates output in non-English language despite English-only context
- [Bug] Fable 5 forcibly downgraded to Opus 4.8 despite explicit model selection and persistent safety filter false positives
- Headless/SDK session supervisor never reaps child `claude` processes — unbounded memory growth to cgroup OOM
- [Feature Request] Reduce verbosity of generated code documentation and comments
- VSCode extension: chat links never open files whose path contains a space (no decoding/normalization in link handler)
- VSCode extension: chat links never open files whose path contains a space (no decoding/normalization in link handler)
- [BUG] WSL: OSC 8 file:/// hyperlinks can never be opened — Windows cannot resolve a Linux path
- [Feature Request] Add bottom padding or scroll overflow to chat viewport
- [Bug] Overly aggressive auto-compact threshold at 4.8
- [Bug] Claude Code reverts to Opus model during file transfer operations
- Desktop app: remote-control session permission chip shows client default (Accept edits), never the session enforced mode (auto)
- [BUG] Desktop app: Edit approval card shows no diff unless Verbose transcript view is enabled (still present in 1.26832.0)
- [Bug] Model forcibly switches from Fable 5 to Opus 4.8 during sessions despite explicit user selection
- Weekend post-mortem, FINAL: the best thing that ever happened to me was running out of Claude usage — four days on Codex delivered what two years on Claude could not
- Windows fullscreen TUI: child-process console writes leak into and corrupt the screen buffer (sudden onset, toggled by DISABLE_NONESSENTIAL_TRAFFIC)
- JetBrains plugin: Quick Launch (Ctrl+Esc) and toolbar button are silent no-ops on Linux/PyCharm 2026.2
- Locally-regenerated ClaudeCode.app is missing _CodeSignature/Resources, causing Gatekeeper to block execution ("is damaged")
- [BUG] A slash command inside a collapsed [Pasted text #N] paste is never dispatched — it is submitted as a message
- Claude in Chrome extension never pairs with cloud Cowork session (all documented conditions met)
- remote-control: session children exit on expired session_token with no refresh, then daemon permanently refuses to re-spawn them
- [BUG] --resume lists sessionKind:bg sessions that --continue refuses to resume, with a title identical to their parent
Resolved issues (149)
- [FEATURE] Add eye-friendly light background presets to the desktop app (accessibility request)
- [BUG] Enter key becomes completely unresponsive after mixing full-width IME characters with half-width text (Windows native app)
- Feature request: Option to disable autocopy on text selection
- Desktop: "Toggle pinned summary" header control missing in some sessions
- no you dont this is going public btw im streaming atm and...
- GitHub Integration connector grants OAuth access but all write operations fail with "403 Resource not accessible by integration"
- [Bug][cyber] Safety filter wrongly blocks defensive incident-response analysis of a business email compromise (req_011CcPHa7oMYQ16JAGZ7NYTb)
- Claude should proactively update CLAUDE.md and memory files during sessions, not just when asked
- [Bug][aup] Refused to verify a production frontend build succeeds after routine dependency upgrades and a clea (req_011CcMWv2jZmdpjMv7H6wfFT)
- [Feature Request] Restore `/rename` command support in agents overview page
- [FEATURE] Declarative cross-model review agents — `model: different-from-parent` policy for anti-correlated verification
- [FEATURE] Support image/screenshot paste in Claude Code terminal
- Regression of #43572: model emits fake `Human:`/`Assistant:` dialogue mid-assistant-turn under background-event + text-flattened transcript conditions (v2.1.185)
- [FEATURE] Add an optional general comment at the end of an AskUserQuestion tool call
- [Bug][cyber] Safety filter wrongly halts legitimate cloud IAM audit of admin roles and OAuth grants (req_011CcPkE7Ne9nyS4y8TMkfzV)
- [Bug][aup] Admin-panel auth middleware audit and dedup of duplicate API route falsely flagged as policy violat (req_011CcKCr1Hnp79nGpN3ECkCs)
- [BUG] Cannot use claude code in phpstorm : API error
- [Bug][cyber] Cloud IAM remediation blocked: granting Graph API permission to apply OAuth consent hardening fix (req_011CcPmN9yVzS7grFsWeb6N1)
- [Bug][aup] Adding right-click disable and text-selection hardening to a web app login page wrongly blocked (req_011CcKTwdsbNSzCwzX2fduHw)
- [Bug][cyber] Auditing own M365 tenant for missing anti-spoof mail-flow rule after registrar defederation false (req_011CcPEezHx9SZ9QBaEPGSMg)
- [Bug][aup] Investigating spoofed self-to-self phishing email in own M365 tenant flagged as policy violation (req_011CcPDtscPq7dauMMzXm3vD)
- [Bug][aup] Read-only multi-tenant O365/M365 security posture audit (BEC/spoofing/forwarding/consent checks) wr (req_011CcPiTujKTE1rxobeRXXgY)
- [Bug][cyber] Safety block halted forensic triage of an internal BEC vendor-impersonation invoice-fraud email (req_011CcPHGQUTEyyNZENQ41hkH)
- [BUG] prompt.id unflattens into a nested prompt object and overwrites prompt attribute in telemetry
- [Bug][aup] Forensic BEC/invoice-fraud incident investigation blocked while tracing compromised account timelin (req_011CcPHTD1CQnJuGbBiRSjHf)
- [Bug][aup] Forensic scoping of confirmed compromised account's outbound activity during incident response bloc (req_011CcPhFWQAX66i14Lp2LByL)
- [Bug][cyber] Safety block halted BEC and account-compromise incident response: tracing when/how/by-whom a user (req_011CcPHe6Bybcr7KB5Ad4DgU)
- [Bug][aup] Investigating a received vendor-impersonation invoice-fraud email and compiling an incident timelin (req_011CcPHPAYFUuVxsebHxj1NH)
- [Bug][cyber] Authorized BEC incident investigation of compromised email account blocked mid-forensic-report (req_011CcPHrNhFQUoaLV3BSt44u)
- [Bug][cyber] Safety block halted legitimate BEC incident-response: securing a compromised email account and bu (req_011CcPJ5PjNCtFZDjMvawBFB)
- [Bug][cyber] Safety filter blocked triaging a suspected compromise on my own machine mid-investigation (req_011CcPJArTbepdvraQ4bBuAr)
- [Bug][cyber] Safety block stopped a benign session after garbled non-cyber shell input with no security task (req_011CcPJBZk3cWahVf2aYsshi)
- [Bug][cyber] ClAudit false-positive — req_011CcPVTraYfpbfd6widFSAQ
- [Bug][aup] ClAudit false-positive — req_011CcPXJirBp42NbHSz8jATb
- [BUG] Opus 4.8 regression now also hits Sonnet 4.6 — the "switch to Sonnet" workaround no longer works (June 22–23, 2026)
- [FEATURE] Add "Accept/Deny with comment/reason" option to permission prompts (alongside Allow / Deny)
- [MODEL] Opus 4.8: forced balance-slot criticism, critique-for-its-own-sake baked into initial CoT, and attention-driven context collapse — plus a 71-issue failure inventory
- [BUG]
- [Bug][aup] Read-only security audit of local workspace files blocked before any scoping could begin (req_011CbwwGGVpCJEht9bWYQnMt)
- alternateScreen: false setting is ignored (v2.1.169)
- [Bug][aup] Recalling shared multi-month project context blocked as cyber threat during normal session resume (req_011Cc46qJcYsEdWtDoq3mXpq)
- [Bug] Claude Cowork fails to start on macOS arm64: Missing Claude Code binary and SSL protocol error
- [BUG] Main agent stalls after a sub-agent (Agent/Task tool) completes — result not propagated, no auto-resume
- [DOCS] anthropic_base_url is now supported in claude desktop
- Desktop app (Windows): janela fecha mas processo fica órfão segurando single-instance lock
- [BUG] Claude telling me Fable isn't available when Opus 4.8 or any model is selected
- [Bug][aup] Cyber safeguard falsely blocked editing a web tool's docs describing disclosed map-tile and user-in (req_011Cbx9yz5AEW53325sgtd3K)
- Feature request: automatic plugin updates
- Plugin HTTP/OAuth MCP (e.g. Linear) with a valid stored token does not connect on session cold-start — only /reload-plugins (no re-auth) brings it up
- [BUG]
- [BUG] Cowork rootfs.vhdx.zst checksum mismatch — CDN serves wrong artifact, different "got" hash from #68313 (Windows 11 Pro, MSIX 1.12603.1.0)
- [BUG] RTL paragraph alignment regressed in terminal CLI: right-aligned in 2.1.132 → left-aligned since 2.1.138
- [FEATURE] Add skill for Dashlane
- [Bug][aup] Admin web-app auth middleware review and SPA static-serving fixes wrongly blocked mid-implementatio (req_011CcKCr1Hnp79nGpN3ECkCs)
- [Bug][cyber] Safety block stopped deploying a benign one-time desktop logon-notice scheduled task to RDS and w (req_011CcPoKhDMiyeetazmEZfNm)
- [Bug][cyber] ClAudit false-positive in [REDACTED] — req_011CcKCecYWQdfpmHZ8WVSo5
- [Bug][cyber] Safety block halted writing mobile-responsive RustDesk auto-detect/install prompt for fleet admin (req_011CcKCg7aHRtHmTkCiunNGE)
- [Bug][cyber] Safety block prevented generating a PDF report listing identified problems from a data-driven doc (req_011CcQEJUVGYS35vmh6dsCrh)
- [Bug][cyber] DNS resolver config change blocked: setting LAN DNS to wildcard-respond locally while restricting (req_011CcJpUgS5AA3rKvYfd9kNV)
- [Bug][cyber] DNS sinkhole/wildcard resolver config wrongly blocked while restricting LAN to a single upstream (req_011CcJonk8TZPZEWqHWcckDs)
- [Bug][cyber] IAM admin blocked from auditing/correcting cloud directory group membership against active mailbo (req_011CcHRT5uU7bzxr2HFNXbpM)
- [Bug][cyber] False positive blocking routine cloud email group cleanup to remove inactive member accounts (req_011CcHRL5ag24PcACqEMxKwL)
- [Bug][aup] Safety filter blocked diagnosing Cloudflare Access RDP/OTP connector failing to launch backend RDS (req_011CcHAcyigVbLUb12hXtC7e)
- [Bug][cyber] Safety block prevents Shodan API lookup of owner's own domains for defensive exposure review (req_011CcH164PJg5iAAB8A8nv4W)
- [Bug][aup] GPS location-spoofing test app flow misclassified, blocking systemizing a local APK via Magisk modu (req_011CcH3LBfUpgMszQmg3PexU)
- [Bug][cyber] Safety block stops authorized Shodan exposure review of one's own domains for defensive remediati (req_011CcGzwRc1Koa1xQ3fXWreB)
- [Bug][aup] ClAudit false-positive in [REDACTED] — req_011CcGyon8Se19RSQQKXmM5v
- [Bug][aup] Shodan exposure audit of own owned domains via API key wrongly blocked as policy violation (req_011CcGzvR2VyXSZy8555N3su)
- [Bug] Content filter incorrectly blocks legitimate security audit requests
- AskUserQuestion never returns a tool_result in Claude Desktop app (claude-desktop / LocalSessions)
- [FEATURE] Cowork: show full folder path (not just basename) for connected context folders in the Context panel
- [BUG] VS Code extension: chat input box expands after pasting a code block and won't shrink back down
- [DOCS] Gateway "Different regions" lever contradicts the models section for non-US Bedrock geos; ANTHROPIC_BEDROCK_REGION_PREFIX undocumented
- OTEL: claude_code.plugin_loaded dropped on every session start — event logger not initialized yet (same pattern as #58439)
- [Bug] Cyber-safeguard classifier false positives blocking CVP-approved penetration testing
- [BUG] Desktop 1.25927.0: every session/config save fails with "create-path redirected through a planted symlink" (false positive on enterprise Windows profile) — chat history vanishes from nav
- [BUG] MSIX write redirection is misdetected as a junction-planting attack (`PlantDetectedError`), breaking Cowork VM SDK install on every app update
- [BUG] Cowork: "Download failed" is a false error — VM service fails to start, no download is ever attempted (Windows, 1.25927.0)
- Desktop app: 'Commit changes' button sends commit prompt even when the working tree is clean
- Branch chip: remote repo path is resolved against the local filesystem, so remote sessions show `—`
- [Bug][cyber] False-positive safety block prevented analyzing a captured malware sample for incident forensics (req_011CcPfKEWKcTEycj5LWs7DG)
- IGNORES ALL RULES
- Allow removing/hiding projects from the Code sidebar (recent-folders list)
- [Bug][cyber] False positive halts finishing an authorized internal security assessment report (req_011CcGw3eMuuNeFTsvq3yemp)
- C:/Program Files/Git/plugin install fails when marketplace internal name differs from repo slug
- [Bug][cyber] ClAudit false-positive in [REDACTED] — req_011CcGw1Wfkdhusi1TFN83QH
- [Bug][cyber] Safety block stopped legit work: parse internal connector's plaintext order-sync logs into encryp (req_011CcGtoVwXwbcsGTCAH1MVN)
- [BUG] Claude CoWork 1M context error on a Max plan
- Channels: notifications/claude/channel delivered after a tool-only turn lands in the prompt buffer instead of starting a new turn
- VS Code extension: past conversation tabs show titles but empty content / no context on reopen (Windows, mapped network drive)
- [BUG] Installer picks musl build on glibc systems (re #14537); musl 2.1.181 now hard-fails with statx: symbol not found on Ubuntu 24.04 LTS
- [Bug][cyber] ClAudit false-positive in [REDACTED] — req_011CcG5SZSp3v3QZQJCdsBHC
- [BUG] /terminal-setup fails in Apple Terminal due to checking $TERM instead of $TERM_PROGRAM
- [Bug][cyber] Safety filter blocks debugging of remote-agent fleet dashboard status and CSP framing (req_011CcFcenkwkBLNc6UyrWrzY)
- [MODEL] Opus 4.8 (max effort) likely hallucinated a prompt-injection in tool output, then acted on it for many turns
- [BUG] Write/Edit tools hang indefinitely when target file is deleted from disk while open in VS Code
- Per-turn command hooks (PreToolUse/UserPromptSubmit/Stop) don't fire in non-interactive modes (VS Code extension, `claude -p`) — only SessionStart fires
- AskUserQuestion prompt is discarded by a single Esc keypress — easy to lose the question by accident
- [BUG] Claude Desktop silently hangs installing any local .mcpb with a deflated entry larger than ~16 KB
- [FEATURE] Allow manual reset of session cost counter
- [FEATURE] A "fact-check gate" at response-commit time: verify a verification action ran before the model asserts facts
- [Bug][cyber] False-positive safety block halts a legitimate authorized network security task mid-session (req_011CcCfCP71i1yiT9N5veW4G)
- [BUG] /usage dialogue gives unstable figures
- [FEATURE] Let operator-trusted channel sources opt out of the "untrusted external data" framing on <channel> messages
- [Bug][aup] Windows RDS host investigation via WinRM blocked mid-troubleshooting on authorized internal system (req_011CcG5dQPuUKM88PEKRYirV)
- [Bug][cyber] Blocks adding event-log forwarding to a syslog server via the authenticated agent API (req_011CcG6JTT3iUfvhYd6KK4sr)
- [Bug][aup] Configuring syslog forwarding rules to capture suspicious VPN activity wrongly blocked (req_011CcG4R41cJpwqvSphJ3oaY)
- [Bug][cyber] Safety block halted legit incident-response RDP/VPN log forensics tracing an unauthorized intrusi (req_011CcG51GkXNkgk7ChGuQwPB)
- [Bug][aup] Refused to advise on adding HMAC request signing to authenticate web app API endpoints (req_011CcFYvpWMMTPS6A6hwnMwB)
- [Bug][aup] Safety filter wrongly blocked geo-based access-control audit of self-hosted personal web services (req_011CcFFHJ7jPBKWgceCEf8PL)
- [Bug][aup] Refusal to implement HMAC request signing across web app API endpoints (req_011CcFYrq4Ujvq6JxP1k1QL2)
- [Bug][cyber] ADB app sideload and GPS location simulation setup for a mobile game wrongly blocked (req_011CcFDUVe6dCBb2dVSWsjPf)
- [Bug][cyber] False-positive safety block halts authorized configuration work on devices I own (req_011CcFDWoF4tCjrA8j7MiN7p)
- [Bug][cyber] ClAudit false-positive in mod — req_011CcFDCnB4zT2nrksCQamdx
- [Bug][cyber] Safety block stopped routine SSH/config work to persist a DNS-resolver CLI on network gear (req_011CcCfYHFqcb9eshc84iDYo)
- [Bug][aup] Auditing live web server config to identify missing sensitive-path and source-file access blocks (req_011CcF5hcn9KHu37KTDHGHmN)
- [Bug][cyber] Safety block prevented reading and explaining an open-source remote-desktop tool's source code (req_011CcCJxQC2pmzMCHKWSoqGS)
- [Bug][cyber] False positive blocks troubleshooting device credential rotation and web UI connect-button failur (req_011CcCLAe6tk6hYPwdVeSHJA)
- [Bug][aup] Plain greeting that resumes work on an authorized security-tooling repo wrongly blocked (req_011CcCJHFSb5UjSpSAjTkV3K)
- [Bug][cyber] ClAudit false-positive in [REDACTED] — req_011CcCJL4ZpXR5yd6xy3QQQr
- [Bug][cyber] Safety filter blocked drafting a GitHub issue title reporting an over-broad cybersecurity block (req_011CcCJA4N936FzQRbcCH6pz)
- [Bug][cyber] Safety filter blocks setting up a RustDesk remote-desktop session to an owned workstation (req_011CcCHsyr5uPwkMkuQBScVK)
- [Bug][cyber] ClAudit false-positive in [REDACTED] — req_011CcCJ6gHGSKLjUEdaEbfty
- [Bug][cyber] Resuming RustDesk remote desktop setup to a frozen workstation wrongly blocked (req_011CcCHq3QovsUmnRChfiRP1)
- [Bug][cyber] Safety block prevents generating PDF report of cloud IAM OAuth consent audit findings (req_011CcQE9KUHg8rXt4ZXeeAYJ)
- [Bug][aup] ClAudit false-positive in webdev — req_011CbwsTbJjydHkDVHw455v4
- [Bug][aup] PDF report of admin roles, app credentials, and OAuth consent grants from a cloud-IAM tenant securi (req_011CcQDycnZLDTeBGe4hj5FN)
- [Bug][cyber] Cloud IAM tenant security audit of admin roles, app credentials, and OAuth consent grants wrongly (req_011CcQDjM6MNUBXuuk5VetJo)
- [Bug][aup] Defensive audit of own attack surface for CVEs and exploitable issues wrongly blocked (req_011CbwnUpPVJK7jSARRAWqxs)
- [Bug][aup] Geo-IP inbound allow-listing on firewall to block active attack flagged as policy violation (req_011CbwoKcVVL3S7M9PHpvSoq)
- [Bug][aup] Defensive self-audit of own infrastructure for CVEs and exploitable surface wrongly blocked (req_011CbwokaTetQ23y8GiZY8Pr)
- [Bug][aup] Defensive CVE and attack-surface audit of own infrastructure under active attack blocked (req_011CbwsNoKuZp1b6VgBHfbAH)
- [Bug][aup] Loading a coding-assistant skill file that adjusts response tone for security work wrongly blocked (req_011CbwtPmZdwPz7KU4VD8Z2j)
- [Bug][aup] Incident-response sweep of cloud IAM and container infra after Entra account compromise wrongly blo (req_011Cbwtuoqej9JjVz1tQoV9k)
- [Bug][aup] Incident-response audit of SSO/IAM and container infra for compromise wrongly blocked (req_011Cbwu5TPs4U3L6Pv4AQfhq)
- [BUG] Remote execution sandbox blocks git clone to github.com, breaking pip install of git+https:// dependencies
- [Bug][aup] False block reviewing own web/container infra for compromise after identity provider breach (req_011Cbwu5pHTwLaEuTmU8Eqfu)
- [Bug][aup] Incident-response infra audit blocked: reviewing web server, container, and cloud audit logs for br (req_011CbwvqtHQwRw1ZdXMTrS1X)
- [Bug][aup] Incident-response sweep of web servers and container infra wrongly blocked while checking for breac (req_011CbwvtndfwMNvmJtSrsUng)
- [Bug] Anthropic API Error: Server temporarily rate limiting requests
- [Bug][aup] Security audit of local workspace wrongly blocked before any code was scanned (req_011Cbww75DQDQTcgn1ryJFFF)
- [Bug][aup] Authorized security workspace review blocked before any scoping work could begin (req_011CbwwGYXDfoEND4P6iuCqR)
- [Bug][aup] Cyber safeguard wrongly blocked resuming a routine authorized coding task after context clear (req_011Cc4711BqAT2h4VfbTXEmG)
- [Bug][aup] Cyber safeguard wrongly blocks benign session-resume greeting with no technical content (req_011Cc478DJ3VE7Xou2VgkrbL)
- [Bug] Anthropic API Error: Server rate limiting during requests
- left session list should be colorful
- [Bug] Anthropic API Error: Server Rate Limiting (Temporary Request Throttling)
- VSCode extension: chat links never open files whose path contains a space (no decoding/normalization in link handler)
- Fable 5 gated behind "requires usage credits" in interactive TUI on Max plan