Claude Code v2.1.232、サブエージェントのフォークをデフォルト化
本文の状態
日本語全文を表示中
詳細モードで約10分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
Claude Code Changelog
Claude Code v2.1.232 は、サブエージェントのフォーク機能常時化やセッション間直接通信機能を追加し、GitLab 統合を強化してセキュリティと開発ワークフローの効率を大幅に向上させた。
AI深層分析を開く2026年8月14日 09:26
AI深層分析
キーポイント
サブエージェントとセッション管理の強化
サブエージェントのフォーク機能がデフォルトで有効化され、会話履歴とプロンプトキャッシュが継承されるようになった。また、@記号による他セッションへの直接メンション機能や、セッション名の重複防止ロジックが導入された。
GitLab 統合の拡大とセキュリティ強化
プラグインマーケットプレイスに GitLab リポジトリ URL の完全サポートが追加され、認証失敗時のヒント機能も実装された。さらに、GitLab トークンファミリーに対するシークレット赤化機能が大幅に拡張され、CLI 設定ストアの保護も強化された。
ガバナンスとセキュリティパッチ
ゲートウェイの設定検証が厳格化され、無効なポリシーやメールドメイン値が起動時に失敗するように変更された。また、PowerShell と Windows における権限バイパスの脆弱性が修正され、ファイルアクセス制御が強化された。
セキュリティと接続の信頼性向上
ネストされたGitリポジトリやリモートコントロールセッションにおける権限継承の問題を修正し、MCP接続のタイムアウト処理も改善した。
エラー表示と回復機能の強化
設定読み込み失敗時のエラー原因明示や、音声サービス拒否時の即時通知に加え、ストリーミングアイドルタイムアウトからの自動回復機能を追加した。
重要な引用
"Subagent forking is now on by default"
"Added secret redaction for GitLab token families"
"Fixed a PowerShell permission bypass"
Fixed nested git repositories inheriting trust from a parent directory; each repository now requires its own trust confirmation
編集コメントを表示
編集コメント
今回のアップデートは、単なる機能追加にとどまらず、エージェント間の連携とセキュリティ基盤の両面を同時に強化した点に意義がある。特に GitLab 環境での利用者が急増する中で、トークン保護や権限制御の厳格化は実務上の必須要件と言える。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
変更点
- サブエージェントのフォーク機能がデフォルトで有効になりました。
subagent_type: "fork"を指定したサブエージェントは、会話履歴とプロンプトキャッシュをすべて引き継ぎます。また、チームメンバーではないエージェントが対話セッションで起動する際も、デフォルトではバックグラウンドで実行されるようになりました。
- プロンプト内で
@を入力すると、別の Claude セッションの名前でメンションできるようになりました。これにより、Claude はSendMessageを使用してそのセッションに直接メッセージを送信します。
「SendMessage」は、リファレンスでの確認を求めず、ライブセッションと完全に一致する単一の名称に対して直接メッセージを送信できるようになりました。
1 台のマシン上のインタラクティブセッションでは、一意の名前が維持されます。既存のライブセッションで既に使用されている名前でセッションを開始したり名前を変更したりした場合、システムは自動的に「name-word-word」形式の変数名を割り当ててユーザーに通知します。
- 「ダイアログの有効期限切れ」および「他のセッションからのメッセージ」(クロスセッションでの着信の受け入れ・保留・拒否)に関する
/config行を追加しました。
- GitLab トークンファミリー(
glrt-、gloas-、glptt-、glagent-、glimt-、glsoat-、glcbt-、glft-、glffct-)に対する機密情報の非表示機能を追加し、ルーティング可能なトークンについても完全な非表示を実施しました。
glpat-やgldt-トークン、およびglab CLIの設定ストアは、同じサンドボックス環境を共有します。
GitHub CLI(gh)における認証パスの保護機能
プラグインマーケットプレイスに GitLab 対応を追加しました。bare な gitlab.com リポジトリ URL(ネストされたサブグループを含む)は、github.com の URL と同様にクローンできるようになりました。また、クローン時の認証失敗時に、実際の Git ホスト名を提示するヒントが表示されるようになりました。
設定:additionalMarketplaces と allowedMarketplaces は、それぞれ extraKnownMarketplaces と strictKnownMarketplaces のより親しみやすい別名として受け入れられるようになりました。
エンタープライズポリシー:裸のリポジトリ URL に対する blockedMarketplaces の url タイプエントリは、CLI がそれを git クローンと分類した場合でも、その URL を引き続きブロックします。
ゲートウェイ:desktop: オーバーレイは、以前は手動でリストアップされた 11 キーのみでしたが、現在はすべての公開された Desktop 設定を受け付けるようになりました。起動時に Desktop 自身のスキーマに対して検証され、不明または無効なキーは起動に失敗します。
- ゲートウェイ:
managed.policies[].match.groupsおよびadmin.admin_groupsのエントリが空の場合、またはemail_domain値に空文字、@、空白、カンマが含まれるといった不正な形式が存在する場合の処理。
起動時に失敗し、誰もマッチしないか管理者権限を付与するのではなく、静かに処理を終了させない。
Fable 5 は、Fable アクセス権を持つ組織向けに、再度 /advisor を通じてアドバイザーとして提供されます。利用クレジットの同意は、/model fable を設定することで完了します。
PowerShell における権限バイパスの脆弱性を修正しました。変数書き込みパラメータが $PSDefaultParameterValues を静かに上書きし、後続のコマンドのファイルアクセスを迂回する事象を防ぎます。
Windows における権限バイパスの脆弱性も修正されました。Git Bash が Cygwin スタイルのシンボリックリンクをたどる際、パス検証では通常ファイルとして認識されていた問題に対し、これらを経由した書き込みには改めて権限承認が必要となりました。
ネストされた Git リポジトリが親ディレクトリから信頼を引き継ぐ挙動を修正しました。現在は各リポジトリごとに独自の信頼確認が必要です。
MCP 接続において、サーバーが応答しないか、プロトコルバージョンプローブに対して不正な返信を送った場合に、30 秒の接続タイムアウトまで接続が停止し続ける不具合を修正しました。
クラウドセッション内でブリッジによってホストされるリモートコントロールセッションが、そのセッションの履歴や認証情報を引き継いでしまう問題を修正しました。
- ローカルセッションを再開した際に、Claude Desktop や IDE から開始されたリモートコントロールセッションが毎回新しい claude.ai セッションとして表示される不具合を修正しました。現在は既存のセッションに再接続されます。
- 待機状態にあるリモートコントロールセッションに対して、新たに接続するクライアントから到達不能と表示されていた不具合を修正しました。
- セッションワーカーが再起動した際に会話履歴が復元されなかったリモートコントロールブリッジセッションの不具合を修正しました。
- Remote Control: claude.ai またはアプリ側でセッションが削除された会話を再開しようとした際、ログインに関するエラーメッセージが表示されて失敗する不具合(v2.1.227 で再発)を修正し、代わりに代替セッションを開始するようにしました。
- 管理設定の読み込みに失敗した際に「Enter キーを押して続行」後にクラウドゲートウェイ
/loginが静かに終了したり、応答しない端末が残ったりする不具合を修正しました。現在はその理由が表示されます。
- ネイティブビルド版で音声モードが接続拒否された際に「聴取中…」の状態で止まってしまう不具合を修正しました。現在は即座に拒否理由が表示されます。
- mTLS 用クライアント証明書のローテーション時に再起動が必要だった不具合を修正し、Claude Code では接続エラー発生時に回転した証明書とキーを自動的に再読み込みするようにしました。
- AWS または Vertex のリージョン値が不正な形式でリクエスト URL を構築していた不具合を修正し、デフォルトのリージョンにフォールバックするようになりました。
- Bedrock、Vertex、およびゲートウェイ展開において、ストリームアイドルタイムアウトエラーが発生した際にリクエストが失敗するのではなく回復するようにする不具合を修正しました。
- コンテンツサイズのオーバーレイで、切り捨てられたテキストが1列分広すぎる状態でレンダリングされていた問題と、先頭から切り捨てられたテキストが省略記号に収束しない問題を修正しました。
長いシェルコマンドやエージェントの説明プレビューが絵文字の途中で切れていた際に表示される不具合な文字を修正しました。
known_marketplaces.json への同時書き込みによって、プラグインマーケットプレイスが静かに登録解除されてしまう可能性のある起動時の競合状態を修正しました。
再起動後に継続する作業が存在する場合に /update および /tui コマンドが再起動を拒否していた不具合を修正しました。
- SDK およびリモートセッションで利用できないスラッシュコマンドを提示する、使用制限に関するガイダンスの誤りを修正しました。
- インタラクティブな
--advisor fableの起動時に、直前に終了したセッション内で/model fableを実行するよう指示していた同意メッセージの誤りを修正しました。
- フルスクリーンのストリーミング機能を改善しました。会話全体を毎回再正規化しなくなったため、長時間のセッションでも応答性が保たれます。
管理設定の承認ダイアログを改善しました。エンドポイント URL の表示、テレメトリのみの変更に対する明確な文言の採用、ルーチンの OpenTelemetry オプションのスキップ、およびサーバー管理によるサンドボックスバイナリオバーライド(sandbox.bwrapPath)への承認要件を追加しています。
sandbox.socatPath、sandbox.ripgrep
/feedbackおよび/bugは、Claude が応答している最中に呼び出された場合、ターン終了を待たずに即座に開くようになりました。
「/plugin install plugin@marketplace」コマンドを実行すると、マーケットプレイスが自動的に最新情報に更新されるため、新しく公開されたプラグインをマニュアルでの更新なしにインストールできるようになりました。
また、「/code-review」コマンドは、高(high)、超高(xhigh)、最大(max)の各設定で実行する際にも、他のレベルと同様にバックグラウンドエージェント上で動作します。
さらに、クリップボードから貼り付けた画像やコピーした画像も、イベントループをブロックすることなく読み込まれるようになりました。
- ネットワークの瞬間的な切断後、リモートコントロールは約30分間再接続を試行し続けます。これまで1時間かけて数回の切断が発生すると接続が切れていたものが、不再断となります。
- リモートコントロール: 同じマシン上で別のClaude Codeが保持している会話の再開時に、そのセッションを無言で奪うことはなくなりました。セッションを引き継ぎたい場合は、そこで
/remote-controlを実行してください。
- エージェントパネルを更新しました。完了したサブエージェントは即座に非表示となり、
/tasksフッターでヒントが表示されます。「↓ N more」というオーバーフローインジケーターも視認性を高めるために左側に移動しました。
- リモートコントロール: 端末では現在、セッションが別のデバイスによって乗っ取られたか、別のアプリから終了されたか、削除されたかを明示します。その操作を無効化する再接続の提案は行われません。
- Bashの入力リダイレクト(
< file)は、すべてのプラットフォームで引数の記述形式と同様に権限チェックが行われるようになりました。
- 完了したバックグラウンドエージェントを再開する際に表示されるメッセージを短縮しました
- コワークセッションでは、ユーザースコープのメモリファイルから外部の @-import をインラインで読み込む処理が削除されました
- 共有
/tmpディレクトリ上に自動生成されたクロスセッション用メッセージングソケットディレクトリのセキュリティを強化しました。事前に植え付けられたシンボリックリンクや他のユーザーのディレクトリが存在する場合は、以前のように使用せず、拒否するように変更されています
Linux ファイルシステムのサンドボックスを強化し、保護されたパスの迂回を防ぎました。
sandbox.ripgrep の設定を変更し、ユーザー設定、管理設定、および --settings 引数からの指定のみが有効となるようにしました。これにより、プロジェクト設定からサンドボックス内の ripgrep バイナリをオーバーライドできなくなりました。
カスタムサブエージェントの作成を促す起動時のヒントと、/powerup ツアー内に対応する通知を削除しました。
原文を表示
What's changed
- Subagent forking is now on by default: a subagent_type: "fork" subagent inherits the full conversation and prompt cache, and non-teammate agent spawns in interactive sessions now run in the background by default
- Type @ in the prompt to mention another Claude session by name; Claude then uses SendMessage to reach that session directly
- SendMessage now delivers to a bare name that exactly matches one live session, instead of asking to confirm with a ref first
- Interactive sessions on one machine now keep unique names: starting or renaming a session to a name another live session already uses gives it a name-word-word variant and tells you
- Added /config rows for "Dialog expiry" and "Messages from your other sessions" (cross-session inbound accept/hold/refuse)
- Added secret redaction for GitLab token families (glrt-, gloas-, glptt-, glagent-, glimt-, glsoat-, glcbt-, glft-, glffct-) and full redaction of routable glpat-/gldt- tokens; the glab CLI config store gets the same sandbox and credential-path protection as gh
- Added GitLab support to plugin marketplaces: bare gitlab.com repo URLs (including nested subgroups) now clone like github.com URLs, and clone auth-failure hints name your actual git host
- Settings: additionalMarketplaces and allowedMarketplaces are now accepted as friendlier aliases for extraKnownMarketplaces and strictKnownMarketplaces
- Enterprise policy: a url-typed blockedMarketplaces entry for a bare repo URL keeps blocking that URL when the CLI classifies it as a git clone
- Gateway: the desktop: overlay now accepts every released Desktop setting (was 11 hand-listed keys), validated at boot against Desktop's own schema; unknown or invalid keys fail boot
- Gateway: empty managed.policies[].match.groups/admin.admin_groups entries and malformed email_domain values (empty, or containing @, whitespace, or commas) now fail at boot instead of silently matching no one or granting admin access
- Fable 5 is offered as an advisor in /advisor again for organizations with Fable access, with usage-credits consent set up through /model fable
- Fixed a PowerShell permission bypass where variable-writing parameters could silently overwrite $PSDefaultParameterValues and redirect later commands' file access
- Fixed a Windows permission bypass where Git Bash followed Cygwin-style symlinks that path validation saw as regular files; writes through them now require permission approval
- Fixed nested git repositories inheriting trust from a parent directory; each repository now requires its own trust confirmation
- Fixed MCP connections hanging for the full 30-second connect timeout when a server fails to answer or sends a malformed reply to the protocol-version probe
- Fixed Remote Control sessions hosted by a bridge inside a cloud session inheriting that session's transcript or credentials
- Fixed Remote Control sessions started from Claude Desktop or an IDE appearing as a new claude.ai session each time the local session was resumed; they now reattach to the existing one
- Fixed Remote Control sessions appearing unreachable to newly attached clients while idle
- Fixed Remote Control bridge sessions not restoring conversation history when the session worker restarts
- Remote Control: resuming a conversation whose session was deleted from claude.ai or the app now starts a replacement instead of failing with a message about your login (regressed in v2.1.227)
- Fixed Cloud gateway /login exiting silently or leaving an unresponsive terminal after "Press Enter to continue" when managed settings failed to load; the reason is now shown
- Fixed voice mode on native builds getting stuck on "listening…" when the voice service rejected the connection; the rejection is now shown immediately
- Fixed mTLS client certificate rotation requiring a restart; Claude Code now reloads the rotated cert and key automatically on connection errors
- Fixed malformed AWS or Vertex region values being used to build request URLs; they now fall back to the default region
- Fixed stream idle timeout errors failing the request instead of recovering on Bedrock, Vertex, and gateway deployments
- Fixed content-sized overlays containing truncated text rendering one column too wide, and start-truncated text collapsing to an ellipsis
- Fixed a stray garbled character where a long shell-command or agent-description preview was cut off mid-emoji
- Fixed a startup race that could silently unregister a plugin marketplace due to concurrent writes to known_marketplaces.json
- Fixed /update and /tui refusing to restart while work that survives the relaunch was running
- Fixed usage-limit guidance suggesting unavailable slash commands in SDK and remote sessions
- Fixed the consent message for interactive --advisor fable launches, which told you to run /model fable in an interactive session that had just exited
- Improved fullscreen streaming: long sessions stay responsive because the whole conversation is no longer re-normalized on every update
- Improved the managed settings approval dialog: shows endpoint URLs, uses clearer wording for telemetry-only changes, skips routine OpenTelemetry options, and requires approval for server-managed sandbox binary overrides (sandbox.bwrapPath, sandbox.socatPath, sandbox.ripgrep)
- /feedback and /bug now open immediately when invoked while Claude is responding, instead of waiting for the turn to finish
- /plugin install plugin@marketplace now refreshes the marketplace first, so newly published plugins install without a manual marketplace update
- /code-review at high, xhigh, and max effort now runs in a background agent like the other levels
- Pasted and clipboard images are read without blocking the event loop
- Remote Control now keeps reconnecting for about 30 minutes after a network blip and no longer drops after a few blips spread across an hour
- Remote Control: resuming a conversation no longer silently takes Remote Control away from another Claude Code on the same machine that still has it; run /remote-control there to move it
- Updated agent panel: completed subagents hide immediately with a /tasks footer hint, and the "↓ N more" overflow indicator moved left for visibility
- Remote Control: the terminal now says whether a session was taken over by another device, ended from another app, or deleted, and stops suggesting a reconnect that would undo it
- Bash input redirections () are now permission-checked like their argument spellings on all platforms
- Shortened the message shown when resuming a completed background agent
- Cowork sessions no longer inline external @-imports from user-scope memory files
- Hardened the auto-generated cross-session messaging socket directory on shared /tmp: a pre-planted symlink or another user's directory is now refused instead of used
- Hardened the Linux filesystem sandbox against a protected-path bypass
- Changed sandbox.ripgrep to be honored only from user, managed, and --settings settings; project settings can no longer override the sandbox's ripgrep binary
- Removed the startup tip suggesting you create custom subagents, and the matching nudge in the /powerup tour
関連記事
News to Guide
ニュースの次に確認する
発表内容を、現在の料金や仕様と照らし合わせられる関連ガイドです。
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み