2.1.222

Claude Code 2.1.222 - リリースノート

2026年8月4日
Claude Code

日本語サマリー

Claude Code 2.1.222 リリースノート要約

⚠️ セキュリティ修正および重要な仕様変更

  • セキュリティ修正: worktree-isolated sessions における破壊的な git コマンドの実行を防止。ファイル編集と Bash コマンドに対してすべてのセッションで分離が適用されるよう修正。
  • セキュリティ修正: PreToolUse auto-allow hooks が、バックグラウンドエージェントタスクでのツール制限をバイパスする問題を修正。
  • 安全性の向上: auto モードにおいて、SendMessage で他のエージェントセッションへ送信されるメッセージが、送信前に権限分類器による評価を受けるよう変更。
  • 仕様変更: Remote Control の自動起動において、リポジトリローカルの設定ファイル(.claude/settings.json および .claude/settings.local.json)からの有効化を廃止(ユーザースコープの /config からの有効化が必要)。
  • 機能削除: ultraplan 機能を削除。

その他の重要な変更点・バグ修正

  • ネットワーク・API 関連: HTTPS プロキシ環境下での起動時の接続チェックのハングアップ、および Connection closed mid-response の誤報を修正。
  • 設定・モデル選択: CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST 設定時、ホストのモデル選択キーがディスク上の古い managed-settings.json より優先されるよう修正。また、組織制限のあるサブエージェント等のエイリアスが適切にフォールバックされるよう修正。
  • 利用状況・クレジット: /usage における MCP サーバーの過大な使用量割り当てを修正。Team および Enterprise での /usage-credits の送信ブロック問題を解消。
  • UI/操作感: /diff ビューなどで textconv 等の設定を無視し、raw git blob content を使用するように改善。画面リーダー(--ax-screen-reader)の読み上げ挙動や、各種スピナー、エラー表示の不具合を修正。
  • 統合・連携: プッシュ後に作成された Pull Request がセッションに正しくリンクされない問題や、無効なトークン時の claude.ai connectors の誤った認証要求表示を修正。

原文(Release Notes)

What's changed

  • Fixed worktree-isolated sessions and their subagents being able to run destructive git commands against the main checkout; isolation now applies to file edits and Bash in every session type
  • Fixed PreToolUse auto-allow hooks bypassing tool restrictions in background agent tasks (summaries, compaction, renames)
  • Fixed /usage-credits on Team and Enterprise showing "you've already sent a usage credit request" for members whose earlier request was dismissed, blocking them from sending a new one
  • Fixed the startup connectivity check hanging and then failing behind an HTTPS proxy; it now uses the same proxy-aware transport as API requests and times out with a clear message
  • Fixed "Connection closed mid-response" errors being reported on responses that had actually completed
  • Fixed /usage overattributing usage to MCP servers: a server's share now reflects only the requests that actually consumed its tool results, instead of every turn after any call to it
  • Fixed sessions not linking to pull requests created after the branch was pushed, including through the GitHub REST API
  • Fixed org-restricted model: opus-style subagent and teammate family aliases dropping to the parent model instead of stepping down to the newest org-allowed model in the family
  • Fixed stream idle timeout firing on custom ANTHROPIC_BASE_URL gateways despite server keep-alive pings arriving on the wire
  • Fixed claude.ai connectors being falsely marked as needing authorization when the session token is invalid — they now show a /login hint instead
  • Fixed tool errors not being displayed for tools no longer available locally, for example after an MCP server is removed
  • Fixed SendMessage rejecting a long summary — it now truncates instead, so sends no longer fail on a character limit
  • Fixed the spinner's effort label in a subagent's transcript view showing the session's effort level instead of the subagent's own effort: setting
  • Fixed rare crashes when a file watcher hit a filesystem error or during file-watcher teardown
  • Fixed screen readers re-reading the whole input line on every backspace in --ax-screen-reader mode — end-of-line deletions now echo just the deleted characters
  • Fixed host model-selection keys not taking precedence over a stale on-disk managed-settings.json when CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST is set
  • Improved auto mode safety: messages sent to other agent sessions via SendMessage are now evaluated by the permission classifier before dispatch
  • Improved the refusal when Claude tries to invoke a skill with disable-model-invocation: Claude is now told to ask you to run the skill instead of replicating its workflow
  • Improved the /diff view, the Remote Control workspace diff, and file-edit diffs in Claude Code on the web sessions to use raw git blob content, ignoring workspace-configured diff drivers and textconv
  • Changed Remote Control auto-start so repo-local settings (.claude/settings.json or .claude/settings.local.json) can no longer turn it on (they can still turn it off); enable it at user scope via /config
  • Removed ultraplan feature