Claude Report — 2026-10-07
- <a href="https://claude.com/resources/articles/claude-now-works-in-google-docs-sheets-and-slides">Claude for Google Workspace</a> launches in public beta same day <a href="https://claude.com/docs/cowork/changelog">Claude Cowork</a> moves to cloud-sandboxes-by-default (Oct 6).
- <a href="https://github.com/anthropics/claude-code/releases/tag/v2.1.292">Claude Code v2.1.292</a> adds marketplace installs and a sub-agent `effort` parameter, a day after v2.1.291's same-day hotfix.
- Anthropic expands both the <a href="https://www.anthropic.com/news/cyber-verification-program">Cyber Verification Program</a> (3 access tiers) and the <a href="https://claude.com/resources/articles/were-expanding-the-claude-startups-program-to-help-founders-build">Claude Startups program</a> during SF Tech Week.
- <a href="https://github.com/anthropics/claude-agent-sdk-typescript/releases">claude-agent-sdk-typescript</a> and <a href="https://github.com/anthropics/claude-agent-sdk-python/releases/tag/v0.2.164">claude-agent-sdk-python</a> both ship Oct 6 releases with new agent/task-tracking fields.
- Plugins and Skills top-lists stay flat; real movement concentrates in Agents (davila7/claude-code-templates) and MCPs (context7, serena, codebase-memory-mcp).
🚀 Anthropic Official
Claude Code v2.1.292 (Oct 6)
Adds a --marketplace <source> flag to claude plugin install that adds the marketplace and installs the plugin in one step, and adds an effort parameter to the Agent tool so Claude can dial a sub-agent's effort level up or down. Ships mod-facing features too: a prompt.autocomplete hook, prompt caching for $.model.complete (cache up to a marked text block), and visibility for mods into workflow-agent spawns via agent.spawn. Bundles 70+ other fixes: sandbox auto-allow hardening, MCP tool names over 128 characters, scheduled-task persistence, and session/plan-mode resumption.
API — Models endpoint reports thinking support (Oct 5)
GET /v1/models and GET /v1/models/{model_id} now return capabilities.thinking.types.disabled, so callers can check whether a model accepts thinking: {type: "disabled"} before trying to turn thinking off.
claude-agent-sdk-typescript v0.3.291 → v0.3.292 (Oct 6)
Reaches parity with Claude Code v2.1.292 and adds its own fields: agent_id on subagent messages, parent_task_id on task_started events, run_id on background-task events, typed sections/notes on the ListAgents tool result, and read_at/arrived_at on ReadNotifications output. Also fixes subagents in auto permission mode wrongly using the classifier instead of the canUseTool callback.
claude-agent-sdk-python v0.2.164 (Oct 6)
Bundles Claude CLI 2.1.292 and hardens CI with an egress-firewall runner, a network allow list, and an enforcement-check workflow for GitHub Actions; raises the PyPI per-file size guard to 250 MiB.
anthropics/sandbox-runtime (Oct 6)
Fixes invalid-upstream-status handling so the proxy now answers with a clean 502 instead of forwarding a malformed status code, continuing the Linux-hardening work from earlier in the window.
Claude for Google Workspace — public beta (Oct 6)
Opens a Claude sidebar inside Google Docs, Sheets, and Slides on all paid plans via the Google Workspace Marketplace, with "ask before edits" or "accept all edits" modes; Claude can write formulas, build pivot tables and charts in Sheets, and match existing deck layouts in Slides. Ships alongside beta Google Docs/Sheets/Slides connectors for Team and Enterprise plans.
Claude Cowork — cloud sandboxes by default (Oct 6)
Moves new Cowork tasks on Pro/Max to per-session cloud sandboxes by default, proxying local files through the desktop app; removes the "Only on your computer" local-execution toggle from Settings. Sandboxes are created at session start and destroyed at the end, share no state across sessions or orgs, and have no outside network access unless an admin allowlists it.
Cyber Verification Program expansion (Oct 6)
Replaces the prior single tier with three: Defense Access (defensive work, few-day review), Red Team Access (authorized pentesting for organizations, few-week review), and Specialized Access (critical infrastructure testing reviewed with the US government). All tiers get Claude Opus 5.5, Sonnet 5.5, and Mythos 5.1 with tier-appropriate reduced safeguards; predecessor program Project Glasswing found 129,000+ verified vulnerabilities (33,000+ critical/high) between April–July 2026.
Claude Startups program expansion (Oct 6)
Adds a free year of Claude Team (up to 5 Premium seats) plus $1,000 in API credits for companies new to Team, up to $45,000 in partner offers via a new "Claude Startup Stack," and hands-on help publishing to Claude Marketplace. Announced at Claude Founder House San Francisco (Oct 6–8); eligibility covers companies founded in the last 5 years or funded in the last 2.
🔌 Claude Code Plugins
Plugin install-count cache is unavailable this run, so top-10-by-installs tracking is skipped per instructions. The only plugin-folder activity found in anthropics/claude-plugins-official inside the window is the security-guidance 2.0.9 → 2.0.10 bump (Oct 5), already reported yesterday with no further evolution since.
🛠️ Skills
None of the top 5 updated in window.
Unchanged in window: anthropics/skills (last commit Oct 5, already reported), kharmanskyi/open-steps (last release v0.4.8, Oct 5, already reported), addyosmani/agent-skills (last commit Oct 3), K-Dense-AI/scientific-agent-skills (latest release still v2.72.0 from Oct 1), cloudflare/security-audit-skill (last commit Sep 14).
🤖 Agents & Subagents
davila7/claude-code-templates (Oct 5–7)
Ships a new jev-skill-typeahead mod that surfaces skill suggestions above the prompt as you type, then fixes it across several follow-up commits (hook wiring, scoring overlap, logging noise, Gateway protocol header); fixes the webfetch-cache mod to key on offset with fail-closed security guards, and renames/enhances the payment-integration agent to payment-gateway-integrator.
Unchanged in window: nicobailon/pi-subagents (last release v0.76.1, Oct 6, already reported), wshobson/agents (last commits Oct 4, already reported), VoltAgent/awesome-claude-code-subagents (last commit Oct 5, already reported), anthropics/commerce-agents (dormant since Aug 31).
🔗 MCPs & Integrations
upstash/context7 (Oct 6)
Ships an MCP server card implementation and corrects tool names in the README, beyond the Oct 5 CLI/docs fixes already reported yesterday.
oraios/serena (Oct 5–6)
Improves language-server classification with fixes across TypeScript, Angular, PHP, Kotlin, Nix, and Erlang integrations; redirects Kotlin's idea.system.path to stop stale /tmp dirs and fixes C# path discovery.
DeusData/codebase-memory-mcp (Oct 5–6)
Adds team artifact bundles and an detect_changes scope:tests end-to-end path, makes test-impact scripts run on Linux GCC with LeakSanitizer, and fixes Windows DACL handling for the security-audit pattern plus a subprocess-exit race in CI.
ChromeDevTools/chrome-devtools-mcp (Oct 6)
Truncates long names to 100 characters by default, beyond the dependency bumps already reported yesterday.
Unchanged in window: graygnatconsole/mcp-audit-tool (last commit Sep 26).
💡 Community — Workflows & Ideas
Piebald-AI/claude-code-system-prompts (Oct 6)
Logs Claude Code v2.1.292's internal system prompt at +7,031 tokens over v2.1.291 (no change), detailing new sections for SDK safety-stop tracking, MCP server background control, and permission-check status events — a concrete, sourced look at what's actually growing inside the prompt.
📰 Quick Mentions
- Claude Desktop v2.26454.0 changelog — bundles Claude Code 2.1.289 and fixes crash/attachment/SSH-session bugs across the desktop app (Oct 6).
- redreamality.com — Cowork's cloud-sandbox shift analyzed — third-party breakdown of the local-VM-vs-cloud-sandbox tradeoffs behind the Oct 6 default change.