Claude Code v2.1.292: one-command marketplace plugin installs, sub-agent effort levels, and network-path read fixes#
Published by Alex Sorokoletov
Part of the Claude Code Version Tracker series. | Official Env Vars | Official Changelog
Claude Code v2.1.292 adds an effort parameter to the Agent tool, so a sub-agent runs at the level you ask for, and a --marketplace flag to claude plugin install that registers a marketplace and installs a plugin from it in one command. A new CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS lengthens backoff on overloaded (529) requests, and a permission-prompt bypass for file reads from network (UNC) paths is closed. It follows v2.1.291.
Sub-agents, plugin installs, and mod hooks#
The Agent tool takes an effort parameter, so Claude runs a sub-agent at the effort level you request rather than a fixed one.[1] claude plugin install gains --marketplace <source>: it adds the marketplace under the same policy checks as claude plugin marketplace add, then installs the plugin from it, folding the former two steps into one.[1]
Mods get three new hook points. prompt.autocomplete lets a mod add its own rows to the prompt box's autocomplete list. $.model.complete now takes prompt caching: prompt and system accept blocks of text, and cache: true on a block caches the request up to it. The agent.spawn hook now receives workflow agents with their run and index, so a mod can refuse one.[1]
Reads from network paths and swapped links#
One fix is labeled a security fix: PreToolUse hook approvals and auto mode no longer skip the permission prompt for file reads from network (UNC) paths.[1] Three related fixes tighten what a read can reach. A notebook or PDF read on macOS and Windows can no longer return a file outside what was approved through a link swapped in mid-read. Sandboxed commands can no longer read the staged file copies of /ultrareview uploads under ~/.claude/seed-admin. A managed read-deny path that appears or re-points mid-session now drops project grants inside it and ends credential injection from the files it covers. On Windows, rm -rf on the 8.3 short name or another alternate spelling of the home folder or a drive is now treated as removing it.[1]
New Environment Variables#
| Variable | What It Does |
|---|---|
CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS | Sets the base delay, in milliseconds, for the backoff when a request comes back overloaded (HTTP 529). The retry loop seeds its wait from this value on overload failures, so a higher number spaces out retries against an overloaded API. Added in v2.1.292. |
CLAUDE_CODE_ARTIFACT_VERSIONS | When set, the session can list and read an artifact's earlier versions; without it, a session reports that an artifact's earlier versions are not available. Reads route through the frame-versions endpoint and return the live version plus its history. Added in v2.1.292. |
CLAUDE_CODE_ARTIFACT_PREVIEW_EMULATOR | Pins the artifact-preview emulator on (true) or off (false); left unset, a feature flag decides. When on, the emulator checks its skill's files first and stays off if they cannot be read. Added in v2.1.292. |
CLAUDE_CODE_HOST_SKILL_CATALOG | A JSON object ({"skills": [...]}) of 1 to 64 folder names that scopes which synced claude.ai skills a remote session loads. It is read only when a remote session id is set, and is ignored with a warning if the shape is wrong. Added in v2.1.292. |
CLAUDE_CODE_MANAGED_CONFIG_PREFETCH | Turns on a hedged prefetch of the organization's managed settings during startup, so the first managed-settings fetch runs earlier in the launch sequence. Added in v2.1.292. |
Resume, scheduled tasks, and startup#
Plan mode is restored when you resume a session from the claude --resume picker or /resume.[1] Scheduled tasks created after /resume, /branch, or /clear now fire, and a background session's /loop survives a process restart instead of stopping silently. NO_PROXY is honored for Claude Code's own API requests (sign-in, policy, feedback, artifacts) when HTTPS_PROXY is set. An MCP tool whose name runs past 128 characters is left out with a named error instead of failing every request. The Artifact tool can list up to 200 published artifacts at once, up from 50. Local (stdio) MCP servers negotiate protocol version 2026-07-28 by default, with MCP_PROTOCOL_NEGOTIATION=legacy to opt out.[1]
What These Tell Us#
Several fixes in this release constrain what a file read can reach. Network (UNC) paths now hit the permission prompt under hook approvals and auto mode, a link swapped in mid-read cannot pull a file outside the approval, and a managed read-deny path that changes mid-session drops grants and ends credential injection inside it. Together they close paths where a read returned more than was approved.
The new artifact variables sit on the hosted surface. CLAUDE_CODE_ARTIFACT_VERSIONS reads an artifact's version history, CLAUDE_CODE_ARTIFACT_PREVIEW_EMULATOR pins a preview emulator on or off, and CLAUDE_CODE_HOST_SKILL_CATALOG scopes which synced skills a remote session loads. These apply to cloud and desktop-hosted sessions more than a plain terminal, alongside the Artifact tool's higher 200-item listing cap.
Plugin distribution is the other thread. --marketplace folds marketplace registration into install, and the build carries a publish confirmation that names the destination (your own shelf on claude.ai or the organization's library) and runs each publish through the usual permission check, with an administrator's publishing policy deciding what the organization allows.
Sources#
- Claude Code Official Changelog, v2.1.292 release notes
This analysis is conducted for educational and research purposes under fair use principles. All trademarks and software referenced belong to their respective owners.
Related Versions#
- Claude Code v2.1.286: model-refusal fallback, permission-prompt counts, safer credential logs
- Claude Code v2.1.285: WebFetch off switch, provider allowlists, plugin configure
- Claude Code v2.1.284: Sonnet 5.5 and auto mode as the default
- Claude Code v2.1.283: exact model allowlists, model deny rules, and grouped gateway requests
- Claude Code v2.1.269: plugin eval reports and Bash command diffs
Previous Claude Code analysis: v2.1.291 (October 6, 2026)
All 66 Claude Code analyses: Claude Code Version Tracker · Official Claude Code changelog