This week in Claude
August 10, 2026
Auto mode becomes Claude Code's default, and a CVSS 9.4 GitHub Actions CVE
Get the next issue in your inbox. Weekly, free.
TLDR;
Auto mode becomes the default in Claude Code for Pro, Max, and Team plans, replacing per-command approval with autonomous runs that flag only dangerous commands. Black Hat USA research disclosed CVE-2026-54316 (CVSS 9.4): a GitHub issue reaching CI could leak a Claude Code API key through Hugging Face's public download counter, one character at a time. Self-hosted runners also entered public beta, letting Team and Enterprise orgs run Claude Code sessions entirely on their own compute.
Sponsored by belt
belt connects your agents to hundreds of tools, mcps, skills. extracts knowledge and patterns from your conversations. surfaces them automatically back to your agent.
your conversations never start cold again and your goals are reached ~6 times faster.
Headline
Auto mode is now the default in Claude Code
Anthropic announced Aug 7 that Claude Code will run auto mode by default for Pro, Max, and Team plans, with the rollout starting the following week. Instead of approving every command, you supervise longer autonomous runs while a safety layer intercepts dangerous commands — Anthropic's pitch is that constant approval prompts train developers to click "yes" without reading, and auto mode catches more real risk. You can switch back per-project or globally (see the permission modes docs). A companion post shows how Nuro, Gusto, and Garner Health run auto mode in production.
Skill of the Week
grilling by Matt Pocock
This week's editor pick. Instead of Claude agreeing with your plan and starting to build, grilling makes it do the opposite: relentlessly interrogate the plan first — assumptions, edge cases, failure modes, things you haven't thought about — before a single line gets written. From Matt Pocock, the TypeScript educator behind Total TypeScript and AI Hero. Cheap insurance against a day of building the wrong thing.
Community Releases
Expo Skills
Official agent skills from the Expo team that teach Claude how to drive Expo CLI, plus an MCP server for triggering EAS builds and checking project status from inside a session. Docs at docs.expo.dev/skills.
OpenPanel MCP Server
The open-source analytics platform now ships an MCP server with 38 tools for querying user and event data from Claude or Cursor — ask your analytics questions in the session where you're already working.
Obsidian Skills Pack by kepano
Obsidian's CEO maintains a skills pack for working with Obsidian vaults — note summarization, article extraction, vault automation. It made the rounds again this week as more people wire Claude into their notes.
1. Claude Code & CLI
Self-hosted runners for Claude Code enter public beta
claude self-hosted-runner is now in public beta for Team and Enterprise plans. It turns your own machines or containers into the execution layer for Claude Code web, mobile, and desktop sessions — keeping code and toolchains inside your network. Two modes: fixed runners (always-on machines) and on-demand runners (spun up per session). Not available for ZDR orgs.
Dynamic Workflows & /effort ultracode
The /workflows command (or a natural-language workflow description) now generates reusable orchestration scripts that fan out tasks to parallel subagents. /effort ultracode sets Claude to maximum reasoning for complex, large-scale work. Generated workflow scripts persist to disk so you can re-execute the same multi-agent pipeline without re-prompting — audit, migration, and cross-checked research are the headline use cases documented.
Skill and Plugin Security Scanning (Beta)
Enterprise plans can now enable automatic security scanning of third-party skills and plugins at upload/edit time. Flagged Aug 6 in the official release notes. If you're an Enterprise admin running a Claude Code deployment with community skills, turn this on before your security team asks you why you haven't.
2. Security
CVE-2026-54316: a GitHub issue could leak your Claude Code API key from CI
Research presented at Black Hat USA 2026 (by Novee) showed how a single crafted GitHub issue could compromise AI coding agents running in CI. In Claude Code, CVE-2026-54316 (CVSS 9.4, NVD) turned Hugging Face's public download counter into an exfiltration channel, leaking an API key one character at a time; versions 0.2.54 through 2.1.163 are affected, fixed in 2.1.163. Gemini CLI's parallel flaw (CVE-2026-12537, a CVSS 10.0 host command injection) is fixed in 0.39.1. If you run Claude Code in CI, confirm you're past 2.1.163 (current releases are — see below) and audit any workflow an outside user can trigger.
3. Competitor Dev Tools
Cursor — Google Workspace Plugins (Aug 3)
Cursor launched Gmail, Google Drive, and Google Calendar plugins that give coding agents direct read/write access to Workspace data from inside the editor. The underlying Google MCP servers are in Developer Preview. Relevant context if you're evaluating Claude Code vs. Cursor for teams with heavy Google Workspace footprints.
Codex CLI v0.147.0 — Agent Plugins + MCP 2026-07-28 (Aug 7)
OpenAI's Codex CLI ships portable Agent Plugins with cross-catalog search, support for the MCP 2026-07-28 protocol (paginated discovery, multi-round requests), Amazon Bedrock caching, and the ability to import Cursor-managed skills. The --approve-for-me flag enables automatically reviewed approvals. Builders evaluating multi-tool agentic setups should note Codex CLI is closing the plugin parity gap with Claude Code's marketplace.
4. Enterprise & Business
Inference hooks: inline data loss prevention for Claude Enterprise
Announced Aug 5. Inference hooks let compliance teams inspect and enforce policy on every prompt and tool-call response before they reach Claude — across Claude Enterprise surfaces including chat, Claude Code, and Cowork. If your org blocked Claude rollout on DLP grounds, this is the feature to re-open that conversation with.
Tino Cuéllar Joins Anthropic as Chief Global Affairs Officer
Former California Supreme Court Justice and ex-Carnegie Endowment president Mariano-Florentino (Tino) Cuéllar joins as Anthropic's first-ever Chief Global Affairs Officer, reporting to President Daniela Amodei. The hire coincided with Anthropic meeting the White House to discuss a voluntary AI safety testing framework — builders on regulated deployments should watch for policy guidance that follows from this appointment.
5. Research & Safety
Improving Fable 5's Biology Safeguards
Anthropic updated Fable 5's biology safeguards to substantially reduce false positives — cutting biology-related fallbacks by about 85% in testing. Total fallbacks from any cause should drop roughly 67% on Claude.ai, 55% on Cowork, 17% on Claude Code, and 7% on the Claude Platform. Virology, toxicology, and molecular design still route to Opus 5 fallbacks; trusted-access pathways for researchers are planned. Builders hitting biology-domain refusals in their applications should retest against the current model.
6. Release Notes
Claude Code:
- v2.1.226 (Aug 8) — Bug fixes and reliability improvements
- v2.1.225 (Aug 8) — Gateway spend-limit support in usage warnings; workspace trust prompt for
claude agents; fixes for OAuth 401 on token refresh, MCP OAuth macOS keychain timeouts, consecutive-block limit miscounting safety-filter refusals, Remote Control session resume after large compacted conversations, and headless cross-session message delivery - v2.1.224 (Aug 7) —
claude self-hosted-runnerin beta;archiveplugin source (zip over HTTPS with SHA-256 pinning); cross-sessionSendMessageandListAgents(macOS and Linux);crossSessionInbound/dialogExpirysettings; sandbox credential masking with JWT-aware decode and AWS SigV4 re-signing; fixes for long project path session directory collisions - v2.1.223 (Aug 6) — Owner wildcard entries (
"owner/*") forstrictKnownMarketplaces/blockedMarketplaces;/teleporthint in cloud sessions; security fixes: Bash permission bypass via crafted commands, tab/Unicode-padded command hiding in approval dialogs, workflow sandboxdynamic import()escape,bypassPermissionsagent definition ignoring org policy; fixes for gateway model discovery hiding prefixed Claude model IDs - v2.1.222 (Aug 4) — Security fix: worktree-isolated sessions could run destructive git commands against the main checkout; security fix:
PreToolUseauto-allow hooks bypassed tool restrictions in background agent tasks; fixes for startup connectivity check hanging behind HTTPS proxies,/usageoverattributing MCP server consumption, stream idle timeout on custom gateway base URLs
Agent SDKs (TypeScript):
- v0.3.226 (Aug 8) — Parity with Claude Code v2.1.226
- v0.3.225 (Aug 8) — Fixed background subagents in headless/SDK sessions never resuming after a background shell command or Monitor completed
- v0.3.224 (Aug 7) — Added
crossSessionInbound/dialogExpirysettings;subkind: 'peer-send-message'ontask-notification;source: 'archive'plugin config; sandbox credential-masking fields (decode: 'jwt',awsPairs/sigv4); fixed long project path session directory collisions - v0.3.223 (Aug 6) —
resumeDropsTurnoption for safe truncating resumes; 529 overload errors now surfaced asapi_error_status: 529in result messages; headless sessions emitsystem/permission_deniedstream events on auto-denied tool calls;usagevsmodelUsageclarified in docs (usemodelUsagefor cost accounting) - v0.3.222 (Aug 4) — Fixed
query({ sessionStore, resume })not carrying usersettings.jsoninto resumed subprocess - v0.3.221 (Aug 4) — Improved
skillsoption validation: malformed names now raise errors; fixed external MCP servers not connecting before the first turn in SDK sessions
Agent SDKs (Python):
- v0.2.134 (Aug 8) — Bundles Claude CLI v2.1.226;
pip install claude-agent-sdk==0.2.134 - v0.2.133 (Aug 8) — Bundles CLI v2.1.225
- v0.2.132 (Aug 7) — Bundles CLI v2.1.224
- v0.2.131 (Aug 6) — Bundles CLI v2.1.223
- v0.2.130 (Aug 4) — Bundles CLI v2.1.222
- v0.2.129 (Aug 4) — Breaking: skill names with delimiters, control characters, wildcards, or leading
/now raiseValueErrorat connect time;skills=["plugin:*"]→ useskills="all"; security fix: crafted skill names could inject extra--allowedToolspermission rules; bundles CLI v2.1.221
Action Items
Immediate:
- Decide your auto mode stance before the rollout — auto mode becomes the default for Pro, Max, and Team plans; if you want per-command approval, set your permission mode explicitly now (per-project or globally).
- Confirm CI runs Claude Code past v2.1.163 and audit externally-triggerable workflows — CVE-2026-54316 (CVSS 9.4, disclosed at Black Hat) leaked API keys from CI via a crafted GitHub issue; the fix landed in 2.1.163.
- Update Python SDK to v0.2.129+ — breaking change:
skills=["plugin:*"]andskills=["*"]now raiseValueError; replace withskills="all"before your next deploy. - Apply the v2.1.222 and v2.1.223 security fixes — worktree-session destructive git commands, PreToolUse auto-allow bypass, Bash permission bypass, Unicode-padded command hiding in approval dialogs, and workflow sandbox
dynamic import()escape are all fixed in the past week's releases.
For Enterprise admins:
- Enable skill and plugin security scanning — available in beta as of Aug 6; turn it on before security reviews ask why third-party skills aren't being scanned on upload.
- Evaluate inference hooks for DLP — inline policy enforcement on every prompt and tool call across Claude Enterprise surfaces; unblocks compliance-gated rollouts.
For Team/Enterprise platform teams:
- Plan self-hosted runner rollout —
claude self-hosted-runneris in public beta; if your organization has network isolation requirements, this week's launch is the entry point; note ZDR orgs are excluded from the beta.
Want to catch up? Read every past issue of This week in Claude.
Did you like this issue?
One tap is the fastest way to shape next week.
And I read every reply. Hit reply and tell me what you want more of, or less of, and it goes straight into the next issue.
Liked this?
Weekly · Free
This week in Claude
Get the next issue every Monday morning. Model updates, releases, and notable tools.
Also available at kit.com.
