2.1.218

Claude Code 2.1.218 - リリースノート

2026年7月22日
Claude Code

日本語サマリー

以下は Claude Code 2.1.218 のリリースノートの要約です。

⚠️ 破壊的変更・セキュリティ修正

  • セキュリティ: 信頼されていないフォルダからの agent frontmatter hooks 実行を制限しました。hooks はエージェントファイル自身のフォルダが workspace trust を受け入れている場合のみ実行されます。
  • 破壊的変更: agent の Markdown ファイルにおいて、プラグインの名前空間として予約されている :(コロン)を含む名前は拒否されるようになりました。
  • 破壊的変更: context: fork を指定した skills は、デフォルトでバックグラウンド実行されるようになりました(background: false でオプトアウト可能)。

💡 主な新機能・改善

  • /code-review の改善: バックグラウンドサブエージェントとして実行されるようになり、会話を占有しなくなりました。
  • auto モードの改善: dangerous-rm、バックグラウンドの &、不審な Windows パスなどのチェックで許可ダイアログが開かなくなり、分類器が自動判定するようになりました。plan mode における Bash コマンドの挙動も改善されています。
  • /deep-research の変更: Claude が自律的に開始するのを取りやめ、手動で呼び出された場合のみ開始するよう変更されました。
  • 設定値の柔軟性: skills や plugin の boolean 値で true/false に加え yes/no/on/off/1/0 が許容されるようになりました。
  • UI/UX改善: fast mode の切り替え通知の追加、サーバー管理の良性設定による承認プロンプトの削除、/mcp での接続エラー詳細の表示などが行われました。

🐛 重要なバグ修正

  • Windows パスの文字化け: \u プレフィックス(例: C:\Users\unicorn)を含むパスが CJK 文字に破損し、ファイルにアクセスできなくなる問題を修正しました。
  • 会話消失の防止: 左矢印キーによる誤った会話破棄を防ぐため、編集直後の操作には確認を求めるようにしました。
  • API・通信ループの修正: thinking budget が大きい状態での context-overflow エラー後の無限リトライループや、リモートセッション終了後の無限ハートビート送信を修正しました。
  • フリーズ・クラッシュの解消: 深くネストされたディレクトリの削除・移動時のスタックオーバーフロー(クラッシュ)や、異常なデータによるセッション再開時のクラッシュを修正しました。
  • 各種コマンドの修正: 複数行ペースト時の改行消失、/ultrareview 引数エラー、システムクロック調整による時間計測のバグなどを修正しました。
  • アクセシビリティ (--ax-screen-reader): 削除キーの読み上げ追加や、画面拡大鏡が矢印キーナビゲーションを追従できるようにするなどの改善を行いました。

原文(Release Notes)

What's changed

  • Changed /code-review to run as a background subagent, so review work no longer fills your conversation and keeps stacked slash commands as its review target
  • Added screen-reader announcements of deleted text for word and line deletions (Option+Delete, Ctrl+W, Cmd+Backspace, Ctrl+U, Ctrl+K) in --ax-screen-reader mode
  • Fixed Windows paths with \u-prefixed segments (like C:\Users\unicorn) being corrupted into CJK characters in tool inputs, which made those files inaccessible
  • Fixed the left arrow key discarding the conversation with no undo: presses right after editing now ask to confirm, and Esc in the agent view returns to the conversation it backgrounded
  • Added HTTP status and error text to claude mcp list and /mcp when a server fails to connect, and a warning for MCP config values with hidden leading or trailing whitespace
  • Fixed multi-line paste collapsing into one line with j in place of newlines in terminals that encode pasted newlines as Ctrl+J
  • Fixed /context reporting stale pre-compact token usage after compacting from the message picker
  • Fixed /ultrareview failing on descriptive arguments like "review my auth changes" — they now run a review of your current branch with the text applied as a note to the findings
  • Fixed /code-review ultra silently running a local review in non-interactive sessions — it now launches the cloud review
  • Fixed gateway spend metering to price Bedrock application-inference-profile ARNs and other config-mapped upstream model IDs at the configured model's rates
  • Fixed mojibake when a long IDE selection was truncated mid-emoji, and a case where a tool executor error could be silently dropped
  • Fixed an engine teardown race that could start and abandon a phantom turn, and made input pushed after close consistently rejected
  • Fixed spurious "[Request interrupted by user]" messages after interrupted tool calls, and an unpaired tool_use block left in the transcript when a tool aborted mid-response
  • Fixed VoiceOver reading "new line" instead of echoing the typed space at the end of the input in --ax-screen-reader mode
  • Fixed plugin and settings panels not moving the terminal cursor to the focused row, so screen readers and magnifiers can follow arrow-key navigation
  • Fixed crashes (maximum call stack exceeded) when a deeply nested watched directory tree was deleted or moved, and when rendering deeply nested UI trees
  • Fixed pull request events occasionally being lost when a session exited immediately after creating or linking a PR
  • Fixed the Bedrock setup wizard failing profile verification for assume-role profiles in partitioned AWS regions and on proxy-only networks
  • Fixed rare negative or incorrect turn duration measurements after a system clock adjustment by timing turns with a monotonic clock
  • Fixed the "N MCP servers need authentication" startup notice over-counting claude.ai connectors that aren't connected in claude.ai
  • Fixed prompt history entries being dropped or duplicated when history writes raced or failed
  • Fixed a retry loop that re-sent identical doomed requests after a context-overflow error with a large thinking budget; Ctrl+B backgrounding now applies the same background-shell caps as other paths
  • Fixed agent frontmatter hooks running from untrusted folders: hooks now require the agent file's own folder to have accepted workspace trust
  • Fixed fork-session lineage being lost after compaction in headless and SDK sessions
  • Fixed a resumed session failing every turn, or crashing on resume, when its history held a malformed delta attachment
  • Improved /ultrareview error feedback so Claude can correct an invalid argument instead of retrying it unchanged
  • Improved auto mode: the dangerous-rm, background-&, and suspicious-Windows-path checks no longer open permission dialogs; the auto-mode classifier adjudicates them instead
  • Improved sandbox command restrictions for IDE interactions
  • Improved trust dialogs to name the repository root the grant covers
  • Changed /deep-research to start only when invoked manually; Claude no longer launches it on its own
  • Changed plan mode with auto to no longer prompt for Bash commands the static analyzer can't prove read-only; the auto-mode classifier judges them instead
  • Added an announcement when fast mode changes as a result of switching models via /config model=<x> or Remote Control
  • Changed server-managed settings so benign feature and cost toggles no longer trigger the settings-approval prompt
  • Changed agent markdown files to reject agent names containing :, which is reserved for plugin namespacing
  • Changed skills with context: fork to run in the background by default; opt out per skill with background: false
  • Added yes/no/on/off/1/0 (case-insensitive) as accepted values for skill and plugin frontmatter booleans, alongside true/false
  • Fixed remote sessions continuing to send heartbeats after their worker was replaced, which left long-lived desktop and IDE processes retrying a rejected request every few seconds forever