№ 1562026-09-29

Claude Report — 2026-09-29


🚀 Anthropic Official

Introducing Claude Sonnet 5.5 (Sep 28)

Ships claude-sonnet-5-5, a faster/cheaper companion to Opus 5.5, holding Sonnet 5 pricing ($2/Mtok in, $10/Mtok out) while running >30% faster and using fewer tokens per task, cutting effective cost up to 30%. Scores 70.6% on Terminal-Bench 4.0 (vs 10.3% for Sonnet 5) and 55.5% on CursorBench, landing within ~2 points of Opus 5.5 on several evals. Available immediately via the Claude API, Amazon Bedrock, Google Cloud/Vertex, and Microsoft Foundry/Azure with zero-data-retention support; Claude Haiku 5.5 is flagged as "coming weeks."

API & Claude Code release notes — Sonnet 5.5 migration notes (Sep 28)

Documents migration caveats tied to the new model: forced tool-use timeout now 400s, thinking blocks are tied to model/conversation and account-bound, computer_20251124 tool no longer accepted on API/GCP, and the advisor tool no longer accepts Opus 4.7/4.8 or Sonnet 5 as advisors.

Claude Code v2.1.284 (Sep 28)

Sets Claude Sonnet 5.5 as the default Sonnet model (1M context); adds a "Yes, but ask again next time" permission option for auto mode; shows dollar-amount spend limits for Claude-apps gateways; adds effort-slider/Ultracode-toggle keybindings and an /mcp reconnect all command; fixes damaged response streams, oversized-image tool-call failures, MCP/plugin/session bugs, vim-mode cursor issues, and permission-rule/sandbox handling.

claude-agent-sdk-python v0.2.161 (Sep 28)

Bumps bundled Claude CLI to 2.1.284, pulling in Sonnet 5.5 support; published to PyPI as claude-agent-sdk==0.2.161.

claude-agent-sdk-typescript v0.3.284 (Sep 28)

Renames skill-directory names in SlashCommand aliases, adds Ultracode availability tracking, and fixes bugs; CLI parity bump to 2.1.284.

anthropics/skills — claude-api skill update (Sep 29)

Sets Claude Opus 5.5 as the default model reference (Opus 5 now "previous"), documents Sonnet 5.5, and adds new build-eval/eval-hillclimb/cost-hillclimb/eval-audit guides plus a preserved-thinking-migration subcommand.

SDK/tooling sync wave (Sep 28)

The rest of the Anthropic toolchain bumped for Sonnet 5.5 support the same day: anthropic-cli v1.36.0 (also bumps Go SDK dep to v1.76.0); anthropic-sdk-python v1.9.0; six synchronized anthropic-sdk-typescript/platform packages (sdk-v0.129.0, bedrock-sdk-v0.34.0, vertex-sdk-v0.20.0, foundry-sdk-v0.5.0, aws-sdk-v0.7.5, google-cloud-sdk-v0.0.15); claude-cookbooks adds model-agnostic caveats for preserved thinking/cache reads/effort; ClaudeForFoundationModels v0.2.2; claude-code-action bumps Claude Code to 2.1.284 and Agent SDK to 0.3.284.

claude-plugins-official — scope-guard fix (Sep 28)

Exempts command sources from the scope-guard source.url check (#6296), a security-hardening follow-up to the Sep 25 Security Plugin v0.12.0 work, even though the repo itself was archived Sep 15 in favor of the new public Plugin Directory.

🔌 Claude Code Plugins

Plugin install-count tracking skipped again this run (official marketplace cache unavailable), per instructions. The only in-window plugin-adjacent activity found was the anthropics/claude-plugins-official scope-guard security fix noted above under Anthropic Official (Sep 28) — the archived repo still receives occasional hardening commits even though it's superseded by the new Plugin Directory.

🛠️ Skills

addyosmani/agent-skills

Merges nine PRs then bumps to manifest v0.6.11 (Sep 26): guards spec/plan/todo artifact paths on every command surface, strips all negated trigger clauses (not just the first), enforces skill-anatomy layout rules, and validates manifest versions against root plugin.json.

anthropics/skills

Updates the claude-api skill for Opus 5.5/Sonnet 5.5 and adds build-eval/hillclimb guides (Sep 29) — see Anthropic Official above.

kharmanskyi/open-steps

Ships v0.4.4 (fixes doctor.sh misjudging installs across Codex/Cursor/Gemini CLI) and v0.4.5 (fixes the os-big-picture census script's permission-matching bug and clarifies ${CLAUDE_SKILL_DIR} guidance), both Sep 28.

Unchanged in window: cloudflare/security-audit-skill (last commit Sep 14), K-Dense-AI/scientific-agent-skills (only an automated scan-report commit Sep 28, no substantive change since Sep 13).

🤖 Agents & Subagents

nicobailon/pi-subagents

Ships four releases (v0.72.0→v0.73.1, Sep 27) plus a security dependency bump (undici 8.10.2, Sep 29) and feature work letting workflows resume reload-stopped work, disable individual subagent features, and scope models via allow tokens.

davila7/claude-code-templates

Adds a Vercel-sandbox mod for running risky Bash commands safely, a "chess" mod where Jev plays instead of Claude, and several agent-template quality improvements (Sep 26-28).

wshobson/agents

Fixes dangling skill reference links via its "gardener" validation tool, adds a macOS connectivity-triage skill to incident-response, and validates generated YAML frontmatter (Sep 26-29).

Unchanged in window: VoltAgent/awesome-claude-code-subagents (last commit Sep 21), anthropics/commerce-agents (last activity Sep 11).

🔗 MCPs & Integrations

DeusData/codebase-memory-mcp

Merges LSP/Python scope-chain performance fixes, a fix so the AST/defs walker grows instead of capping on large files, Windows unicode-git-root and mkstemp/errno fixes, and a cppcheck nullable-strcmp security fix (Sep 27-28).

upstash/context7

Fixes the claude-plugin to match the official plugin and drops an unneeded API key header (Sep 28), plus a docs fix for the default dev port and a test-suite change routing through OpenRouter.

graygnatconsole/mcp-audit-tool

Launches (Sep 26) as a dependency-light Python CLI scanning Claude Desktop/Cursor/VS Code MCP configs for tool poisoning, rug-pulls, hardcoded secrets, and command injection, producing letter-grade scores plus SARIF/JSON output for CI; 97 stars in 3 days.

ChromeDevTools/chrome-devtools-mcp

Ships a security fix escaping client-supplied values in MCP context logs/errors (Sep 29) and hardens input validation to reject JSON arrays as third-party/WebMCP tool params (Sep 28).

Unchanged in window: oraios/serena (last commit Sep 24), github/github-mcp-server (last commit Sep 16), modelcontextprotocol/servers (last commit Sep 22).

💡 Community — Workflows & Ideas

ahmed-alstaty/guardrails-plugin

Ships a Claude Code plugin that blocks destructive commands and secret-file edits before they run, prints an OK/WARN/SKIPPED session report of what loaded, and lints CLAUDE.md (posted to HN Sep 27).

kolezka/self-improvement-loop

Releases a Claude Code plugin that reflects on sessions in the background and automatically promotes recurring lessons into new skills (pushed Sep 29).

rkolesnichenko/ccdrift

Ships a drift-detection tool that flags silent changes in Claude Code's prompt caching, Haiku routing, settings, context, and hooks between CLI versions (pushed Sep 29).

nguyenvanphituoc/shapeup-sdlc-plugin

Implements Shape Up methodology gates for coding agents, enforced via non-bypassable PreToolUse hooks (pushed Sep 29, 3 stars).

VoKhoiNhon/open-skill-standard

Proposes an agent-agnostic skill standard across IT roles, explicitly extending the Claude SKILL.md file pattern (created Sep 29, 6 stars).

📰 Quick Mentions

  • talktome — lets a coding agent (Claude Code et al.) place a voice call to the user when it needs input or approval (HN, Sep 26-27).
  • agent-flow — self-bootstrapping, self-healing agent engineering skill installable into any repo (created Sep 26).
  • codex-context-bridge — Codex SessionStart hook that injects Claude Code's own context (CLAUDE.local.md, rules, auto-memory) into Codex sessions (created Sep 29).
  • setup-doctor — scores and suggests improvements for an AI coding-agent setup, doctor-style health check (created Sep 29).
  • corral — kills every child process a Claude Code agent spawns, for runaway-command safety (HN).
  • jauvex — two-way voice-chat harness spanning Claude, Codex, Grok and "Jev" agents, v1.2 released in window (HN).
  • tvty (Terminal Velocity) — combined tickets/loops/focus-tracking tool wrapped around Claude Code sessions (HN).
  • Distributed Claude Code via a tunnelling service — architecture write-up on running Claude Code across machines through a tunnel layer (HN).
← back to archiveend of edition № 156