Claude Code 2.1.292, released on 2026-10-06, adds an effort field to the Agent tool and makes every local stdio MCP connection negotiate protocol version 2026-07-28 by default, including Bedrock, Vertex, and Foundry installations. Use MCP_PROTOCOL_NEGOTIATION=legacy claude for the old handshake. The same release tightens UNC file-read prompts and waits for headless background work to finish.
Key facts about Claude Code 2.1.292
- Anthropic's changelog feed lists Claude Code v2.1.292 at 2026-10-06T18:59:09Z.
- The release contains 92 changes: 46 fixes, 20 security updates, 11 improvements, 8 new features, 3 performance changes, 3 breaking changes, and 1 developer-experience change.
- The
Agenttool acceptseffortvalues oflow,medium,high,xhigh, andmax. - Local stdio MCP connections query support for protocol
2026-07-28by default on every installation, including AWS Bedrock, Google Cloud Vertex, and Microsoft Foundry.MCP_PROTOCOL_NEGOTIATION=legacyopts out. - A local stdio server that takes too long for the newer protocol check is remembered for 7 days and reconnected through the legacy path without waiting again.
- Version 2.1.292 stops UNC file reads from bypassing permission prompts and keeps background commands alive in one-shot
claude -pand Agent SDK runs.
How does Claude Code 2.1.292 set a subagent's effort?
Claude Code 2.1.292 passes effort on the call that creates a subagent. Anthropic's changelog describes the change plainly: "Added an effort parameter to the Agent tool, so Claude runs a sub-agent at the effort level you ask for." The changelog feed is the primary source.
The 2.1.292 package declaration records five allowed values:
effort?: "low" | "medium" | "high" | "xhigh" | "max";The declaration also says to set effort only when the user or an instruction such as CLAUDE.md or a skill explicitly requests a level. Otherwise, omit it and let the subagent use its normal effort. That rule matters for orchestrators. A lead agent should not silently force a lower or higher level because it guesses that a child task is easy or difficult.
Classmethod's 2026-10-07 test found that low was accepted but the subagent did not identify the level, while medium produced a higher reported value than low. max returned the expected max response, and the unsupported value ultra failed with an InputValidationError. The test is useful evidence that the input is validated, but it is not a benchmark of answer quality. For broader orchestration patterns, see Five ways a lead agent runs a crew.
How does Claude Code 2.1.292 negotiate local MCP?
Claude Code 2.1.292 changes the default for local stdio MCP servers. It asks whether the server supports protocol 2026-07-28. A compatible server uses that version. A server that does not support it uses the legacy handshake. The default applies to installations using Bedrock, Vertex, and Foundry as well as the regular Claude Code runtime.
To keep the legacy behavior, start Claude Code with the documented environment variable:
# Opt out of MCP 2026-07-28 negotiation for local stdio MCP servers in Claude Code v2.1.292
MCP_PROTOCOL_NEGOTIATION=legacy claudeThe release remembers a slow stdio connection for 7 days. After the first slow check, Claude Code reconnects through the older method without making the user wait through the same check again. In the v2 MCP client runtime, a channel server that negotiates 2026-07-28 cannot deliver channel messages and is not registered as a channel. That is a client-runtime detail, not a claim that every MCP server must change its implementation. See Why a remote MCP server answers 405 after the 2026-07-28 revision for the separate HTTP failure mode.
What security and headless-execution fixes matter in Claude Code 2.1.292?
Claude Code 2.1.292 changes several permission and unattended-run paths:
- PreToolUse hook approvals and auto mode no longer bypass the permission prompt when reading a network UNC path such as
\\server\\share\\file. - A subagent definition with
permissionMode: autono longer enters auto mode when settings disable it, a circuit breaker blocks it, or the selected model does not support it. - In version 2.1.292, Windows destructive-command checks catch
rm -rfaimed at a home directory or drive through an 8.3 short name or another alternate path spelling. - One-shot
claude -pand Agent SDK runs wait for background commands and scheduled wakeups instead of stopping a background command 5 seconds after the final result. - If an MCP tool name exceeds 128 characters, Claude Code leaves that tool out and reports an MCP error instead of letting the name make every request fail.
The release also adds a single-step marketplace option to plugin installation:
# Install plugin and add marketplace in one step (new in Claude Code v2.1.292)
claude plugin install <plugin-name> --marketplace <owner>/<repo>These fixes matter most when Claude Code runs in scripts, CI, Windows network shares, or plugin-heavy environments. What changed in Claude Code during September 2026? covers the model and permission changes documented for September 2026.
How does Claude Code 2.1.291 compare with 2.1.292?
Claude Code 2.1.291 was a two-fix release published on 2026-10-06. Version 2.1.292 followed with the effort parameter, the MCP negotiation default, security fixes, and headless-run changes.
Change | Claude Code 2.1.291 | Claude Code 2.1.292 |
|---|---|---|
Agent-tool effort | Not listed in the release entry |
|
Local stdio MCP default | Legacy behavior on third-party provider installations | Negotiates |
Headless background commands | Not listed in the release entry | Waited for instead of being stopped after 5 seconds |
If the issue is remote MCP launched from a Windows executor rather than local stdio negotiation, see Codex CLI 0.160.1 preserves Windows environment variables for remote MCP.
Sources
- Claude Code Changelog Feed (read 2026-10-07)
- Claude Code v2.1.292 Major Updates (read 2026-10-07)
- Claude Code 2.1.292 effort and stdio MCP changes (read 2026-10-07)
- Anthropic Claude Platform: Effort Documentation (read 2026-10-07)
Last verified: 2026-10-07.