Claude Code v2.1.221、VSCode でツール活動の非表示機能を追加
本文の状態
日本語全文を表示中
詳細モードで約8分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
Claude Code Changelog
Claude Code のバージョン v2.1.221 がリリースされ、セキュリティ強化による権限チェックの修正や、Linux におけるサンドボックス認証ファイルの新しいマスキング機能、およびセッション管理の不具合修正が行われた。
AI深層分析を開く2026年8月4日 09:30
AI深層分析
キーポイント
セキュリティ脆弱性の修正と権限強化
Bash ツールのパーミッションチェックバイパスや PowerShell のパス処理ミスが修正され、隠れたコマンドの実行を防止するよう強化された。
Linux 向けサンドボックス認証機能の追加
Linux および WSL 環境で「mask」モードが導入され、サンドボックス化されたコマンドがセネチルコピーを読み込む仕組みが実装された。
開発体験とセッション管理の不具合修正
MCP サーバーの接続タイミングや、ファイルの @ 指定が削除される不具合、セッション名更新の同期問題などが解消された。
Vimモードとプラグインの動作改善
Vimモードでのyankレジスタがダイアログや履歴検索でも保持されるようになり、プラグインのインストール時にリロードを不要とするケースが増えた。また、ターミナル内蔵コマンド名を持つスキルが非対話セッションでも呼び出せるようになった。
コスト削減と統計機能の強化
自動モードでの権限チェックにキャッシュを再利用することでプロンプトキャッシュのコストが削減され、ステータスパネルにはキャッシュトークンの内訳が表示されるようになった。
重要な引用
Fixed a Bash tool permission-check bypass where zsh could execute hidden commands in [[ ]] regex conditionals
Added mode: "mask" for sandbox credential files on Linux and WSL
Fixed @-mentioned files being silently dropped when pressing Esc to retract a prompt
Improved Stats panel to count cache tokens in its token totals, with a breakdown by input, output, cache read, and cache write
編集コメントを表示
編集コメント
今回のアップデートは、昨今の AI エージェントツールの普及に伴い高まるセキュリティ要件への対応と、複雑な環境(Linux/WSL)での安定性向上に焦点を当てた内容である。特に権限チェックのバイパス修正は、実運用における重大なリスクを未然に防ぐ重要な措置と言える。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
変更点
- [VSCode] フォーカスビューを追加しました。これはチャットメニューの切り替え機能で、ツールの実行状況を折りたたみ可能な各ターンごとのサマリー内に隠し、実行中のツールを示すライブインジケーターを表示します。
Ctrl+Alt+Fキーまたは「Claude Code: Toggle Focus view」コマンドで切り替えることができます。
Linux および WSL 環境において、サンドボックス認証ファイルに mode: "mask" を追加しました。これにより、サンドボックス化されたコマンドは、完全なファイルまたは extract レギュラー表現でキャプチャされたスパンのいずれかである「シンボル付きコピー」を読み取ります。一方、エグレス時にはサンドボックスプロキシが実際の値に置換します。macOS 環境では、ファイルマスキングはデフォルトで deny にフォールバックされます。
Claude Desktop の管理市場同期で Marketplace またはプラグイン名が拒否される可能性がある場合、claude plugin validate コマンドに警告を追加しました。
「claude-api」スキルに新しいサブコマンド「prompt-audit」を追加しました。これにより、古いモデル向けに記述されたパターンがプロンプトやツール説明に含まれていないか監査できるようになりました。
Bash ツールの権限チェック回避バグを修正しました。このバグでは zsh が [[ ]] 正規表現条件式内で隠しコマンドを実行できていましたが、修正により該当するコマンド実行時に権限確認の要求が表示されるようになりました。
Windows 環境で、引用符を含むパスに対する PowerShell の権限チェックが誤って処理されていた問題を修正しました。これにより、そのようなパスでは改めて承認を求められるようになりました。
セッション開始時に「思考」機能がオフになっていた場合、その後の設定変更が無視される不具合を修正しました。また、接続中に MCP サーバーを無効化しても、以前のように静かに設定が元に戻ってしまう現象も解消されました。
print モード(-p)で、初回のターン前に --mcp-config から指定された MCP サーバーが接続されていない不具合を修正しました。この問題により、モデルがツール呼び出しを文字列として出力してしまう現象が発生していました。
- プロンプトを撤回して再送信する際に、@で指定したファイルが静かに削除される不具合を修正
- 組み込みオブジェクトのプロパティ(例:
constructorなど)と同じ名前の SDK MCP ツールに対して API リクエストを準備する際にクラッシュする不具合を修正 - 「思考」機能を無効化している状態で、試行レベルを
xhighまたはmaxに設定した WebSearch が 400 エラーで失敗する不具合を修正
- サンボックスプロキシ経由での大規模アップロード時に TLS エラーが発生していた問題を修正しました
- チームおよびエンタープライズプランで、支出制限の警告メッセージが組織ごとの月間上限を指すのではなく、個人ごとの支出上限を正しく示さない不具合を修正しました
- Windows 端末で誤って
HOME環境変数が設定されている場合に発生していた、デスクトップ管理セッションでの AWS SSO 名プロファイルを使用した Bedrock 認証の問題を修正しました
CLAUDE_CODE_RESUME_INTERRUPTED_TURN=0を設定しても、中断されたタスクの自動再開がオフにならない不具合を修正しました。現在は偽値(falsy values)も正しく認識されるようになりました。
- スリープからの復帰時に稀に発生する競合状態を修正しました。この状態で 2 つの Claude Code プロセスが同時に同じ MCP コネクタや WIF OAuth トークンを更新しようとすると、再認証を強制されてしまう問題がありました。
- Claude Code Desktop や claude.ai からセッション名を変更しても、CLI のセッション名が反映されない不具合を修正しました。現在はすべての変更箇所から取得したセッション名が適切にサニタイズされるようになりました。
- 端末固有の組み込みコマンド(例:
/help、/feedback)と同じ名前を持つプラグインや組織提供のスキルが、非対話型セッションで呼び出せなくなる不具合を修正しました。
- プラグインを再読み込みした後に「Plugins changed」通知が消えない不具合を修正しました。現在は正しく通知がクリアされるようになりました。
Vim モードの修正:yank レジスタがダイアログ、履歴検索、トランスクリプトビューで消去されなくなりました。
Vim モードの修正:空のプロンプトまで巻き戻した際、「←キーをもう一度押して確認」する前にエージェントビューに戻る動作が追加されました。
Google Vertex AI でのツール検索機能の改善:Claude 4.5 世代以降のモデルで再有効化されました。
自動モードの改善:並列ツール呼び出しに対する権限チェックのキャッシュ効率が向上し、チェック待ち中にモードを切り替えた際にも、古い結果が適用されることなく確実にプロンプトが表示されるようになりました。
自動モードの権限チェックにおけるプロンプトキャッシュコストの削減:意思決定間でキャッシュされた会話プレフィックスを再利用することで実現しました。
統計パネルの改善:トークン総数にキャッシュトークンをカウントし、入力・出力・キャッシュ読み取り・キャッシュ書き込みごとの内訳を表示するように改良されました。
/ultrareview コマンドのエラーメッセージの改善:リポジトリがベースと履歴を共有していない場合、ブランチのないチェックアウトは最初から拒否され、作成するようアドバイスされます。また、既に完全なクローンに対して git fetch --unshallow を実行するよう提案するメッセージは表示されなくなりました。
Windows 起動時の改善:プロセス作成時間の取得に PowerShell を起動する代わりにネイティブの kernel32 コールを使用するため、powershell.exe の実行を制限するエンドポイントセキュリティツールによるプロンプトが発生しなくなりました。
バックグラウンドセッションの変更:作業を保存するためにコミットとプッシュを実行し、タスクで必要とされる場合のみドラフト PR を作成します。CLAUDE.md に記載された git 指示に従い、最後に作業がどこに保存されたかを報告するよう動作を変更しました。
- plugin install コマンドを変更し、マーケットプレイスのカタログが古くなっている場合に更新して再試行するようになり、プラグインが見つからないと報告される前に自動的にリトライします。
/pluginからインストールされたプラグインは、以前のように常に/reload-pluginsを実行する必要がなくなり、安全な状態であれば即座にアクティブ化されるようになりました。 (原文の技術表記:/plugin install)
- プラグインが "
skills" パスとして"."を受け付けるように変更され、ルートレベルのSKILL.mdの検証エラーでは、プラグインのルートを使用するよう提案されるようになりました。
/statusの表示内容を更新し、セッションの種類を明示するようにしました。対話型(interactive)か、アタッチされているか非アタッチ状態のバックグラウンドジョブかを区別して表示します。 (原文の技術表記:attached、unattended)
絵文字の自動補完機能を更新し、:thumbsup: や :thumbsdown:、:love: といった一般的な別名ショートコードも受け付けるようになりました。
/forkでフォークされたセッションは、元のセッションのチェックアウト上ではなく、独自のワークツリーを作成するように変更されました。- Chrome 内の Claude は、不要になったブラウザタブを自動的に閉じるようになりました。
- ファストモードでは、セッション中に利用クレジットが不足した場合に、静かに失敗するのではなく、ストリーム上でその旨を報告するように変更されました。
- Monitor の仕様を変更しました。監視対象が終了しても出力を生成しない場合、以前のように「ストリームが終了」と表示するのではなく、その状態を明示的に伝えるようになりました。
- Gateway の
modelフィールドの検証ルールを変更し、文字列でない値を受け付けないようにしました。これにより、400 エラーとして返却されるようになり、不正な値が転送されるのを防ぎます。 - 承認プロンプトで表示されていた、「自動モード分類呼び出しがキューイングされている間に許可モードが変更されました」という重複する通知を削除しました。
原文を表示
What's changed
- [VSCode] Added Focus view: a chat-menu toggle that hides tool activity behind an expandable per-turn summary with a live running-tool indicator, toggled with Ctrl+Alt+F or the "Claude Code: Toggle Focus view" command
- Added mode: "mask" for sandbox credential files on Linux and WSL — sandboxed commands read a sentinel copy (the whole file, or just the spans captured by an extract regex) while the sandbox proxy substitutes the real value on egress; on macOS file masking falls back to deny
- Added warnings to claude plugin validate when a marketplace or plugin name would be rejected by Claude Desktop's managed marketplace sync
- Added a prompt-audit subcommand to the claude-api skill for auditing prompts and tool descriptions for patterns written for older models
- Fixed a Bash tool permission-check bypass where zsh could execute hidden commands in [[ ]] regex conditionals; affected commands now prompt for permission
- Fixed PowerShell permission checks mishandling paths containing quote characters on Windows; such paths now prompt for approval
- Fixed the thinking toggle having no effect for the rest of a session that started with thinking off; disabling an MCP server mid-connect no longer silently reverts
- Fixed MCP servers from --mcp-config not being connected before the first turn in print mode (-p), which made the model emit tool calls as literal text
- Fixed @-mentioned files being silently dropped when pressing Esc to retract a prompt and resubmitting it
- Fixed a crash when preparing API requests for SDK MCP tools named after built-in object properties such as constructor
- Fixed WebSearch failing with a 400 error at effort xhigh/max when thinking is disabled
- Fixed sandboxed large uploads failing with TLS errors through the sandbox proxy
- Fixed Team and Enterprise spend-limit message incorrectly blaming the org's monthly limit instead of your individual spend limit
- Fixed Bedrock authentication with AWS SSO named profiles failing in desktop-managed sessions on Windows machines that set a stray HOME environment variable
- Fixed CLAUDE_CODE_RESUME_INTERRUPTED_TURN=0 not disabling interrupted-turn auto-resume; falsy values are now honored
- Fixed a rare wake-from-sleep race where two Claude Code processes could both refresh the same MCP connector or WIF OAuth token at once, forcing re-authentication
- Fixed renaming a session from Claude Code Desktop or claude.ai not updating the CLI's session name; session names from every rename surface are now sanitized
- Fixed plugin- and org-delivered skills named after terminal-only built-ins (e.g. /help, /feedback) being un-invocable in non-interactive sessions
- Fixed the "Plugins changed" notification lingering after plugins were reloaded instead of clearing
- Fixed Vim mode: the yank register now survives dialogs, history search, and the transcript view instead of being silently emptied
- Fixed Vim mode: undoing back to an empty prompt now arms the "press ← again" confirm before returning to the agent view
- Improved tool search on Google Vertex AI: re-enabled for Claude 4.5-generation and newer models
- Improved auto mode: permission checks for parallel tool calls are now cache-efficient, and switching modes while a check is pending reliably prompts instead of applying the stale result
- Reduced prompt-cache costs for auto-mode permission checks by reusing the cached conversation prefix across decisions
- Improved Stats panel to count cache tokens in its token totals, with a breakdown by input, output, cache read, and cache write
- Improved /ultrareview error messages when a repo shares no history with its base: a checkout with no branches is now refused up front with advice to create one, and refusal hints no longer suggest git fetch --unshallow on clones that are already complete
- Improved Windows startup: process creation times are now read via a native kernel32 call instead of spawning PowerShell, so endpoint security tools that gate powershell.exe no longer prompt
- Changed background sessions to commit and push to preserve work, open a draft PR only when the task calls for one, follow your CLAUDE.md git instructions, and always end by reporting where the work lives
- Changed /plugin install to refresh a stale marketplace catalog and retry before reporting a plugin not found
- Changed plugins installed from /plugin to activate immediately when safe, instead of always requiring /reload-plugins
- Changed plugins to accept "." as a skills path, and the root-level SKILL.md validation error now suggests using the plugin root
- Changed /status to show the session kind: interactive, or a background job that is attached or unattended
- Changed emoji autocomplete to accept common alternate shortcodes like :thumbsup:, :thumbsdown:, and :love:
- Changed sessions forked with /fork to create a new worktree of their own instead of working in the original session's checkout
- Changed Claude in Chrome to close the browser tabs it opens once it no longer needs them
- Changed fast mode to report on the stream when usage credits run out mid-session, instead of failing silently
- Changed Monitor: a watch that exits without producing any output now says so instead of reporting "stream ended"
- Changed the Gateway model field validation: non-string values are rejected with a 400 instead of being forwarded
- Removed the repeated "Permission mode changed while the auto-mode classifier call was queued" notice from approval prompts
AI算出
主要ニュースainew評価高い
AI コーディングエージェントの主要ツールである Claude Code の機能更新とセキュリティ修正を詳細に記述しており、開発者にとって実用的かつ重要な情報であるため primary_news に分類する。ただし、日本固有の発表や規制変更ではないため japan_relevance は低めとする。
6つの評価軸を見る
- AI関連度
- 100
- 情報源の信頼性
- 100
- 新規性
- 75
- 調べる価値
- 100
- 重複の少なさ
- 100
- 日本での有用性
- 25
関連記事
News to Guide
ニュースの次に確認する
発表内容を、現在の料金や仕様と照らし合わせられる関連ガイドです。
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み