30+ fixes focusing on security & UX. Credential masking should improve practical sandbox operations.
Claude Code v2.1.221 Released — Security Fixes and UI Refinements
Original: v2.1.221
Importance: セキュリティ脆弱性の修正とユーザー体験改善が主だが、マイナーバージョンアップであり破壊的変更や本番影響なし
Summary
Claude Code v2.1.221 released with new Focus view in VSCode to hide tool details behind per-turn summaries, credential masking on Linux/WSL, and 30+ bug fixes. Patches permission-check bypasses in Bash/PowerShell, fixes MCP server connection issues, WebSearch errors at high effort levels, and improves token counting in Stats panel to include cache metrics. Also corrects team/enterprise spend-limit messaging and AWS SSO authentication on Windows.
Key Points
- Fixed Bash/PowerShell permission-check bypass vulnerabilities
- Added credential masking (mode: "mask") on Linux/WSL
- Added Focus view to VSCode (Ctrl+Alt+F to hide tool details)
- Improved MCP server connection and cache token counting
- Re-enabled tool search on Google Vertex AI for Claude 4.5+
View developer notes (APIs, breaking changes, migration)
v2.1.221 fixes Bash zsh `[[ ]]` regex bypass allowing hidden command execution, PowerShell quote-handling permission-check bypass. Adds `mode: "mask"` for credential file sandboxing on Linux/WSL (sentinel copy read in sandbox, real value substituted on egress via sandbox proxy). Fixes MCP servers from `--mcp-config` not connecting before first turn in print mode (`-p`). Stats panel now counts cache tokens with breakdown by input, output, cache read, cache write. Re-enables tool search on Google Vertex AI for Claude 4.5+ models. New `prompt-audit` subcommand for auditing prompts/tool descriptions against older model patterns.
Source: https://github.com/anthropics/claude-code/releases/tag/v2.1.221
Outlet: Claude Code Releases
This article is an AI-generated summary (OpenAI GPT-4o-mini) of publicly available information from Anthropic, OpenAI, Google, Meta, Mistral, DeepSeek, Sakana, and other vendors. The original source URL is always provided in accordance with fair-use citation requirements. Summaries are AI-generated and may contain mistranslations or misinterpretations. Always verify details with the original source.