1382026-09-11

Claude Report — 2026-09-11


🚀 Anthropic Official

Claude Code v2.1.268 (Sep 10)

Adds Claude-apps gateway pricing integration, a gatewayInternalNetworks managed setting, claude self-hosted-runner --remove-session-state, and a startup warning for empty access_control.allow_cidrs. Fixes HTTP 400 errors on third-party endpoints (a regression from 2.1.265), WebFetch hanging indefinitely (now times out at 300s), high idle-CPU usage, and several permission/sandbox bugs.

Claude Agent SDK TypeScript v0.3.268 (Sep 10)

Adds result_index, local_command, hold_on_cache_impact, resume_reason, and kind fields to session events; improves model-confirmation flow and tool defaults, mirroring Claude Code v2.1.268.

Claude Managed Agents — "auto" permission mode (Sep 10)

Introduces a new auto permission policy that lets the server evaluate each agent/MCP tool call and run, deny, or pause it, reported via an evaluation field on agent.tool_use/agent.mcp_tool_use events. The ant CLI gains ant beta:sessions connect (with a --web flag) to attach a terminal to a live Managed Agents session for monitoring and approving tool calls.

anthropic-sdk-python v1.5.0 (Sep 10)

Adds auto-mode tool permissions for Managed Agents, a content_too_large web_fetch error code, Message.to_param()/BetaMessage.to_param(), public GitHub repo mounting without an auth token, and lets tool objects be passed directly to messages.create/parse/stream/count_tokens. Fixes credentials-file permission validation and streaming partial-JSON handling.

anthropic-sdk-typescript v0.125.0 (+ vertex-sdk v0.19.8, foundry-sdk v0.4.6, bedrock-sdk v0.33.5, aws-sdk v0.7.1) (Sep 10)

Ships the same feature set as the Python v1.5.0 release across every deployment surface: Managed Agents auto permissions, the content_too_large error code, a user-profiles beta, and GitHub repo mounting.

Detecting and countering misuse of AI: September 2026 (Sep 10)

A threat-intelligence report covering Dec 2025–Aug 2026 misuse cases across seven harm areas — state-sponsored cyber-ops (GTG-20006/Midnight Blizzard, GTG-50014/ShinyHunters using multi-agent frameworks for autonomous recon/exploitation), nine disrupted influence operations (Russia, Iran, Turkey, Gulf states), autonomous zero-day development (GTG-10007), and alleged undisclosed distillation: DeepSeek reportedly relayed 12.1M user exchanges to Claude Opus in July 2026, and Alibaba-attributed activity totaled 151M+ exchanges (May–Jul 2026).

anthropics/commerce-agents (Sep 10)

Publishes an open-source reference blueprint for Shopping/Merchant agents, runnable via the Messages API, Claude Agent SDK, or Managed Agents with custom MCP servers; ships a /scaffold-commerce-agent Claude Code plugin command with staged writes and provenance gates (no live checkout).

The Python Agent SDK remains stalled at v0.2.152 (Sep 2), with no release in this window despite the rest of the SDK family shipping in lockstep on Sep 10.

🔌 Claude Code Plugins

Plugin tracking skipped this run — official marketplace install-count cache unavailable.

🛠️ Skills

tt-a1i/archify

Adds Gitee and local-only repo support to its evidence pipeline (Sep 8, #354) and modularizes its viewer source while preserving standalone-HTML output (Sep 11, #381).

agentskillexchange/skills

Adds a new "ledger-tasks-yylo" skill (Sep 11), on top of its usual automated sync churn.

K-Dense-AI/scientific-agent-skills

Closes two gaps in the skill-link contract and fixes what they surface (Sep 10, #258), touching the statsmodels, database-lookup, fiscal-data, and simpy skills.

ayghri/i-have-adhd

Trending hard (39.7k stars, +3,882 in a day); ships fixes to OpenCode plugin registration and Windows drivers (Sep 8) and four doc/path-fix PRs for Zed and AstronClaw installs (Sep 10) for its cross-agent "direct, action-oriented response" skill.

Unchanged in window: anthropics/skills (no commits under any skills path), alirezarezvani/claude-skills (no push since Aug 26).

🤖 Agents & Subagents

anthropics/claude-agent-sdk-typescript

See Anthropic Official above — v0.3.268 (Sep 10) adds new session-event fields and improves model-confirmation flow.

anthropics/commerce-agents

See Anthropic Official above — new open-source reference blueprint (Sep 10) for Shopping/Merchant agents with a scaffold command and provenance-gated staged writes.

Unchanged in window: nicobailon/pi-subagents (already-reported v0.67.0 from Sep 10, no further release), VoltAgent/awesome-claude-code-subagents (no commits since Sep 7), claude-agent-sdk-python (still v0.2.152), AMAP-ML/LongHorizon-Harness (no push since Aug 20).

🔗 MCPs & Integrations

github/github-mcp-server

Fixes OAuth protected-resource metadata to advertise only default scopes, keeping the full scope catalog available for per-tool step-up auth challenges (Sep 8, #3251), plus a Go base-image bump.

oraios/serena

Fixes a health-check that falsely reported success when a reference search actually failed (Sep 8, #1998) and disables automatic type acquisition in TypeScript language-server backends (#1990).

modelcontextprotocol/typescript-sdk

Fixes the client so an OAuth-derived Authorization header overrides a caller-supplied header (Sep 11, #2475).

upstash/context7

Enables docs-page feedback controls (Sep 9, #3172), beyond its already-reported Sep 8 on-premise and Vercel OIDC additions.

Unchanged/no new evolution: DeusData/codebase-memory-mcp (continues active development — e.g. Windows PATH cleanup on uninstall, #2117 — but overlaps with already-reported Sep 8-9 fixes), modelcontextprotocol/servers (no commits since Sep 3), punkpeye/awesome-mcp-servers (routine list churn only, Sep 8 docs-link addition).

💡 Community — Workflows & Ideas

roblambert9/skillproof-verifications (Sep 10)

Runs 63–228 adversarial operations per server against official MCP servers, issuing signed Ed25519 Trust Manifests; 4 of 5 servers fail, with SSRF, SQL-injection escapes, and arbitrary file-write vulnerabilities found (only the filesystem server passes).

fuckbigtech-ai/homestead-memory (Sep 10)

Ships Claude Code hooks that log every tool call into a hash-chained, tamper-evident JSONL audit trail with optional Ed25519 signing, measuring roughly 124ms median overhead per call.

hesreallyhim/awesome-claude-code — Sep 8 batch

Adds "Netresearch Agentic Skills" (#2785), a new OSS category (#2782), and "OSS Autopilot" (#2781), ahead of its already-reported Sep 9-10 tooling and backfill PRs.

cathrynlavery/diagram-design

Normalizes rgba()/transparent handling in its PowerPoint SVG importer (Sep 8, #151) and adds a GitHub Copilot marketplace install guide (Sep 10, #218), beyond its already-reported waterfall-chart and Excalidraw-import features.

📰 Quick Mentions

← back to archiveend of edition № 138