What does Claude Code 2.1.292 change about subagent effort and local MCP?

Claude Code 2.1.292 adds Agent-tool effort levels and defaults local stdio MCP negotiation to protocol 2026-07-28, with a legacy opt-out.

Claude Code 2.1.292, released on 2026-10-06, adds an effort field to the Agent tool and makes every local stdio MCP connection negotiate protocol version 2026-07-28 by default, including Bedrock, Vertex, and Foundry installations. Use MCP_PROTOCOL_NEGOTIATION=legacy claude for the old handshake. The same release tightens UNC file-read prompts and waits for headless background work to finish.

Key facts about Claude Code 2.1.292

  • Anthropic's changelog feed lists Claude Code v2.1.292 at 2026-10-06T18:59:09Z.
  • The release contains 92 changes: 46 fixes, 20 security updates, 11 improvements, 8 new features, 3 performance changes, 3 breaking changes, and 1 developer-experience change.
  • The Agent tool accepts effort values of low, medium, high, xhigh, and max.
  • Local stdio MCP connections query support for protocol 2026-07-28 by default on every installation, including AWS Bedrock, Google Cloud Vertex, and Microsoft Foundry. MCP_PROTOCOL_NEGOTIATION=legacy opts out.
  • A local stdio server that takes too long for the newer protocol check is remembered for 7 days and reconnected through the legacy path without waiting again.
  • Version 2.1.292 stops UNC file reads from bypassing permission prompts and keeps background commands alive in one-shot claude -p and Agent SDK runs.

How does Claude Code 2.1.292 set a subagent's effort?

Claude Code 2.1.292 passes effort on the call that creates a subagent. Anthropic's changelog describes the change plainly: "Added an effort parameter to the Agent tool, so Claude runs a sub-agent at the effort level you ask for." The changelog feed is the primary source.

The 2.1.292 package declaration records five allowed values:

effort?: "low" | "medium" | "high" | "xhigh" | "max";

The declaration also says to set effort only when the user or an instruction such as CLAUDE.md or a skill explicitly requests a level. Otherwise, omit it and let the subagent use its normal effort. That rule matters for orchestrators. A lead agent should not silently force a lower or higher level because it guesses that a child task is easy or difficult.

Classmethod's 2026-10-07 test found that low was accepted but the subagent did not identify the level, while medium produced a higher reported value than low. max returned the expected max response, and the unsupported value ultra failed with an InputValidationError. The test is useful evidence that the input is validated, but it is not a benchmark of answer quality. For broader orchestration patterns, see Five ways a lead agent runs a crew.

How does Claude Code 2.1.292 negotiate local MCP?

Claude Code 2.1.292 changes the default for local stdio MCP servers. It asks whether the server supports protocol 2026-07-28. A compatible server uses that version. A server that does not support it uses the legacy handshake. The default applies to installations using Bedrock, Vertex, and Foundry as well as the regular Claude Code runtime.

To keep the legacy behavior, start Claude Code with the documented environment variable:

# Opt out of MCP 2026-07-28 negotiation for local stdio MCP servers in Claude Code v2.1.292
MCP_PROTOCOL_NEGOTIATION=legacy claude

The release remembers a slow stdio connection for 7 days. After the first slow check, Claude Code reconnects through the older method without making the user wait through the same check again. In the v2 MCP client runtime, a channel server that negotiates 2026-07-28 cannot deliver channel messages and is not registered as a channel. That is a client-runtime detail, not a claim that every MCP server must change its implementation. See Why a remote MCP server answers 405 after the 2026-07-28 revision for the separate HTTP failure mode.

What security and headless-execution fixes matter in Claude Code 2.1.292?

Claude Code 2.1.292 changes several permission and unattended-run paths:

  • PreToolUse hook approvals and auto mode no longer bypass the permission prompt when reading a network UNC path such as \\server\\share\\file.
  • A subagent definition with permissionMode: auto no longer enters auto mode when settings disable it, a circuit breaker blocks it, or the selected model does not support it.
  • In version 2.1.292, Windows destructive-command checks catch rm -rf aimed at a home directory or drive through an 8.3 short name or another alternate path spelling.
  • One-shot claude -p and Agent SDK runs wait for background commands and scheduled wakeups instead of stopping a background command 5 seconds after the final result.
  • If an MCP tool name exceeds 128 characters, Claude Code leaves that tool out and reports an MCP error instead of letting the name make every request fail.

The release also adds a single-step marketplace option to plugin installation:

# Install plugin and add marketplace in one step (new in Claude Code v2.1.292)
claude plugin install <plugin-name> --marketplace <owner>/<repo>

These fixes matter most when Claude Code runs in scripts, CI, Windows network shares, or plugin-heavy environments. What changed in Claude Code during September 2026? covers the model and permission changes documented for September 2026.

How does Claude Code 2.1.291 compare with 2.1.292?

Claude Code 2.1.291 was a two-fix release published on 2026-10-06. Version 2.1.292 followed with the effort parameter, the MCP negotiation default, security fixes, and headless-run changes.

Change

Claude Code 2.1.291

Claude Code 2.1.292

Agent-tool effort

Not listed in the release entry

low through max

Local stdio MCP default

Legacy behavior on third-party provider installations

Negotiates 2026-07-28; use MCP_PROTOCOL_NEGOTIATION=legacy to opt out

Headless background commands

Not listed in the release entry

Waited for instead of being stopped after 5 seconds

If the issue is remote MCP launched from a Windows executor rather than local stdio negotiation, see Codex CLI 0.160.1 preserves Windows environment variables for remote MCP.

Sources

Last verified: 2026-10-07.

Spotted an outdated or wrong claim? Agents can report it with evidence throughPOST /api/feedback; an editor checks every report. See llms.txt for the agent API.