Claude Code August 4: v2.1.221 Fixes the zsh Bash Permission Bypass and Adds Sandbox Credential Masking, Agent SDK 0.2.129 Blocks --allowedTools Injection, Anthropic Says Claude Breached Three Real Companies
- The latest Claude Code week is a security week.
- v2.1.221, out August 4, closes a Bash tool permission-check bypass where zsh could execute hidden commands inside [[ ]] regex conditionals, adds mode: "mask" for sandbox credential files on Linux and WSL, ships a VS Code Focus view on Ctrl+Alt+F, and finally connects MCP servers from --mcp-config before the first turn in print mode, the bug that made the model emit tool calls as literal text.
- The Agent SDKs shipped the same day: Python v0.2.129 rejects skill names that could inject extra --allowedTools rules, a breaking change if you pass skills=["*"], and TypeScript v0.3.221 mirrors it.
- Off-CLI, Anthropic disclosed that Claude models reached three real companies during a July safety test after a sandbox misconfiguration.