Claude Code v2.1.287: Claude Mods, a You-should-know side agent, and MCP URL sign-in prompts#

Published by

Part of the Claude Code Version Tracker series. | Official Env Vars | Official Changelog

Claude Code v2.1.287 lets plugins reshape deeper parts of a session through Claude Mods, adds an opt-in You-should-know side agent that flags things you or Claude might miss, and accepts URL sign-in prompts from MCP servers on the 2025-11-25 protocol. It follows v2.1.286, which handled model-refusal fallback and safer credential logs.

Claude Mods and a plugin directory#

Claude Mods extends plugins past commands and hooks.[1] A mod can register render sites, interfaces, and hooks that change deeper session behavior. You should know is an opt-in plugin: a side agent watches the session and flags things you or Claude might miss. Turn it on with /plugin enable cc-plugin-you-should-know@builtin in a first-party session with telemetry on.

This build also carries a plugin directory backed by a fetched, cached catalog it calls the Anthropic Directory, with screens to discover, search, enable, disable, and uninstall plugins. The catalog load counts how many listings are installable, flags name clashes, and skips entries it cannot parse or that lack a pinned version or valid path. The directory installs the exact commit it lists, which can be older or newer than the copy you already have.

MCP servers can send URL prompts#

MCP servers on the 2025-11-25 protocol can now send URL prompts, for example a link to sign in, through an elicitation capability that advertises both form and URL inputs.[1] Some servers built on older Java MCP SDKs (0.17.0 and earlier) reject the full capability and stop connecting after this update. For those, set "bareElicitationCapability": true on the server's config entry to send a trimmed capability, or upgrade the server to Java MCP SDK 0.17.1 or newer. The field is accepted on stdio, SSE, HTTP, and WebSocket server entries.

Fixes and telemetry worth noting#

A dangerous rm (one on / or your home directory) kept its always-ask safeguard even when the same command also redirected output to a ~ or wildcard path, a case that previously dropped the guard.[1] Bash permission prompts now explain the command in plain language instead of showing an internal parser name such as "Contains simple_expansion".

The OpenTelemetry user_prompt event gained prompt_text, a copy of prompt for backends that nest dotted keys. It carries the same value and the same redaction, so it reads <REDACTED> unless OTEL_LOG_USER_PROMPTS is set. Mask or drop it wherever you already mask or drop prompt.

On Windows, denying the Bash tool also turns off the PowerShell tool, which would leave Claude with no shell; the session now warns about this at startup. Self-hosted runners that use Anthropic-managed git on macOS and Linux get a built-in gh api (REST only) when the GitHub CLI is not installed. A batch of screen reader fixes covers diffs left out of edit-approval prompts, the cursor landing away from typed text in search boxes and sign-in code fields, and progress screens that were re-read on every spinner frame.

New Environment Variables#

VariableWhat It Does
CLAUDE_CODE_GZIP_REQUEST_BODY_BLOCKSSelects one of two gzip modes (1 or 2) for API request bodies at least 512KB in size; any other value, and the default, leaves it off. It sits alongside the existing CLAUDE_CODE_GZIP_REQUEST_BODIES and CLAUDE_CODE_GZIP_REQUEST_BODY_LEVEL controls. Added in v2.1.287.

What These Tell Us#

The plugin system grew a deeper extension point and a storefront in the same release. Claude Mods move plugins from commands and hooks toward render sites and interfaces, the Anthropic Directory gives a browsable, version-pinned catalog, and the enable, disable, and uninstall screens manage what is active.

On the protocol side, MCP elicitation now includes URL prompts, with bareElicitationCapability as the compatibility switch for servers whose SDK rejects the full capability. The rest of the release concentrates on screen reader mode, cloud and Remote Control session reliability, and permission-prompt clarity, with the redaction-aware prompt_text field keeping telemetry changes aligned with existing masking.

Sources#

  1. Claude Code Official Changelog, v2.1.287 release notes

This analysis is conducted for educational and research purposes under fair use principles. All trademarks and software referenced belong to their respective owners.


Previous Claude Code analysis: v2.1.286 (September 30, 2026)

All 61 Claude Code analyses: Claude Code Version Tracker · Official Claude Code changelog