Claude Report — 2026-08-09
- Claude Code ships <a href="https://github.com/anthropics/claude-code/releases/tag/v2.1.223">v2.1.223</a>→<a href="https://github.com/anthropics/claude-code/releases/tag/v2.1.226">v2.1.226</a> (Aug 6-8): self-hosted-runner environments, archive plugin installs, cross-session `SendMessage`, plus fixes for a Bash permission bypass and a workflow sandbox escape.
- Anthropic <a href="https://www.anthropic.com/news/improving-fable-5-s-biology-safeguards">retunes Fable 5's biology safeguards</a> (Aug 7), cutting benign-query fallbacks ~85%; critics note the promised researcher access program for frontier biology capability still isn't live.
- Independent evaluator Trajectory Labs reports zero successful breaches across 720 prompt-injection attempts against Claude Code's incoming default auto mode; Simon Willison still wants OS-level sandboxing over classifier-based checks.
- Claude Agent SDK TypeScript/Python ship in lockstep with each CLI release (v0.3.223-226, v0.2.131-134); v0.3.224/v0.2.132 (Aug 7) mirror the new self-hosted-runner and cross-session-messaging features.
- Community trackers: pi-subagents ships two more releases, oraios/serena adds Deno and Gleam language-server support, DeusData/codebase-memory-mcp keeps hardening its release pipeline.
🚀 Anthropic Official
Claude Code v2.1.223 → v2.1.226
- v2.1.223 (Aug 6): fixes a Bash permission-check bypass via crafted/padded commands and a workflow sandbox escape via dynamic
import(); adds owner-wildcard marketplace allow/block entries and a subagent-model-restriction warning. - v2.1.224 (Aug 7, 04:00 UTC): adds self-hosted environments (
claude self-hosted-runnerfor Team/Enterprise), an archive plugin source (install from a zip over HTTPS with optional SHA-256 pinning), cross-sessionSendMessage(Claude Code sessions message each other across machines), and sandbox credential-masking for structured env values and JWTs; removes the 200-subagent-per-session spawn cap; fixes a sandbox filesystem deny-rule bypass on Linux/macOS and a plugin-install-record corruption bug. - v2.1.225 (Aug 8, 01:09 UTC): adds gateway spend-limit support to usage warnings and a workspace-trust prompt for
claude agents; fixes OAuth token/session bugs, macOS MCP 401 bursts, and Remote Control history corruption. - v2.1.226 (Aug 8, 02:48 UTC): "bug fixes and reliability improvements," no itemized changes published.
- Mirrors: claude-agent-sdk-typescript v0.3.223-226 and claude-agent-sdk-python v0.2.131-134 ship in lockstep; v0.3.224/v0.2.132 (Aug 7) carry the same self-hosted-runner and cross-session-messaging features as v2.1.224.
Improving Fable 5's Biology Safeguards
Rewrites and retrains Fable 5's biology-safety classifier "constitution" (Aug 7), cutting biology-related fallbacks on benign queries by roughly 85% and total refusal volume by up to 67% on claude.ai, 55% on Cowork, and 17% on Claude Code; queries touching virology, toxicology, and molecular/drug design still route to the less-capable Opus 5, and Anthropic says trusted-access programs for vetted researchers are still in development.
🔌 Claude Code Plugins
Plugin install-rank cache unavailable this cycle — top-10 install-rank tracking skipped per this run's instructions.
🛠️ Skills
agentskillexchange/skills
Adds an OutageDeck dependency-outage-triage skill (Aug 6) and an ImagineVid AI Generation skill plus a quick-start install-guidance fix (Aug 8), continuing daily ASE catalog syncs through Aug 9.
Piebald-AI/claude-code-system-prompts
Captures the v2.1.224 system-prompt diff (+32,958 tokens — its largest jump this cycle) alongside v2.1.225 (+1,314 tokens) and v2.1.226 (no changes), tracking each CLI release above (Aug 6-8).
Unchanged in window: anthropics/skills (last updated Aug 7, already reported), JSONbored/awesome-claude (last Jul 31), alirezarezvani/claude-skills (last Jul 17).
🤖 Agents & Subagents
anthropics/claude-agent-sdk-typescript
Ships v0.3.223 (Aug 6) through v0.3.226 (Aug 8); v0.3.224 (Aug 7) adds crossSessionInbound/dialogExpiry settings, an archive plugin-source variant, and sandbox credential-masking fields matching Claude Code v2.1.224.
nicobailon/pi-subagents
Ships v0.44.0 (Aug 8) adding automatic mission enclosure and durable workflow state for plain script launches, then v0.45.0 (Aug 9) adding structured terminal-completion payloads to subagent_wait tool results.
Unchanged in window: AMAP-ML/LongHorizon-Harness (last Aug 7, already reported), Chachamaru127/claude-code-harness (last Aug 8, already reported), VoltAgent/awesome-claude-code-subagents (last Jul 31), wshobson/agents (last Jul 18), 0xmmo/crew (last Jul 22).
🔗 MCPs & Integrations
DeusData/codebase-memory-mcp
Continues hardening its release pipeline (Aug 8-9): isolates release-archive downloads, externalizes runtime UI assets, tightens VirusTotal verification, and fixes Windows-specific packaging races.
oraios/serena
Adds Deno language-server support (Aug 6) and Gleam language support plus macOS tray-manager fixes (Aug 8).
Unchanged in window: awslabs/mcp (last Aug 7, already reported), github/github-mcp-server (last Aug 7, already reported), modelcontextprotocol/python-sdk (last Jul 28, v2.0.0), modelcontextprotocol/typescript-sdk (last Jul 27), shlokkhemani/rabbithole (last Jul 29).
💡 Community — Workflows & Ideas
Simon Willison — auto mode default critique
Reacts (Aug 8) to Anthropic's Aug 14 auto-mode default, welcoming the safety gain over manual approval but pressing for independent verification and OS-level sandboxing over classifier-based checks; flags the incoming Trajectory Labs third-party evaluation.
Trajectory Labs independent auto-mode evaluation
Runs 720 indirect-prompt-injection attempts (72 scenarios × 10) against Claude Fable 5/Opus 5/Sonnet 5 under auto mode with zero successful breaches, versus a 5.83% success rate for GPT-5.6 Sol under Codex's auto-review mode; results circulate Aug 9, though malicious third-party packages remain an acknowledged gap.
Forkast — Fable 5 safeguards vs. Stanford's open-weight Evo models
Notes (Aug 7) that Anthropic loosened Fable 5's biology restrictions the same day Stanford/Arc Institute published Evo-model results showing AI-designed functional viral genomes, arguing Anthropic is positioning closed-source safety governance as a competitive moat ahead of its planned October 2026 IPO.
📰 Quick Mentions
- CVE-2026-54316 disclosure — Hugging Face's public download counter was turned into a Claude Code API-key exfiltration channel; fixed since v2.1.163, detailed at Black Hat USA (Aug 7).
- TechTimes — flags that Fable 5's promised trusted-researcher access program for advanced biology capability still isn't live even as clinician-facing restrictions loosen (Aug 8).
- Hackaday — This Week in Security — roundup covering Claude Code exploitation research alongside hotel-WiFi and npm-compromise stories (Aug 7).
- claude-code-action v1.0.187-189 — parity bumps mirroring Claude Code v2.1.224-226 (Aug 7-8).