Security pass fixes worktree isolation gaps (destructive git commands) and hook bypasses in background tasks; Remote Control auto-start now needs /config, ultraplan removed.
SendMessage are now evaluated by the permission classifier before dispatchdisable-model-invocation: Claude is now told to ask you to run the skill instead of replicating its workflow/diff view, the Remote Control workspace diff, and file-edit diffs in Claude Code on the web sessions to use raw git blob content, ignoring workspace-configured diff drivers and textconv/usage-credits on Team and Enterprise showing "you've already sent a usage credit request" for members whose earlier request was dismissed, blocking them from sending a new one/usage overattributing usage to MCP servers: a server's share now reflects only the requests that actually consumed its tool results, instead of every turn after any call to itmodel: opus-style subagent and teammate family aliases dropping to the parent model instead of stepping down to the newest org-allowed model in the familyANTHROPIC_BASE_URL gateways despite server keep-alive pings arriving on the wire/login hint insteadSendMessage rejecting a long summary — it now truncates instead, so sends no longer fail on a character limiteffort: setting--ax-screen-reader mode — end-of-line deletions now echo just the deleted charactersmanaged-settings.json when CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST is set.claude/settings.json or .claude/settings.local.json) can no longer turn it on (they can still turn it off); enable it at user scope via /config