Claude Code Daily Briefing - 2026-10-03
Release Summary
| Version | Date | Key Changes |
|---|---|---|
| v2.1.288 | 10/2 | Added /code-review --max-findings, a re-authentication prompt for expanded MCP OAuth scopes, Ctrl+F session search, and 95+ more changes |
| v2.1.287 | 10/1 | Added Claude Mods and the You should know side agent, switched Opus 4.7+/Fable to 1M context by default, and 110+ more changes (covered in the 10/2 briefing) |
| v2.1.286 | 9/30 | Permission prompt counter, VSCode Bookmarks/Questions, and 90+ more changes (covered in the 10/1 briefing) |
v2.1.288 landed just a day after v2.1.287 on 10/1. Most of the work goes toward hardening session resume, auto mode, MCP, and plugin stability rather than shipping new features, but the result-count option for /code-review and the improved MCP authentication flow stand out.
New Features & Practical Usage
/code-review --max-findings — take direct control of how many findings a review reports (v2.1.288)
/code-review now accepts a --max-findings <n>|all option, letting you report more or fewer findings than the usual cap. Once set, the value sticks until you run --max-findings default.
# Report up to 30 findings
/code-review --max-findings 30
# Report everything, no cap
/code-review --max-findings all
# Reset to the default
/code-review --max-findings default
Large PRs used to hit the default cap and lose important findings in the cutoff — now you can tune the review’s scope to match the project or PR, getting either a thorough deep-dive or a tighter summary on demand. Full release notes
MCP servers requesting broader OAuth scopes now trigger a re-authentication prompt (v2.1.288)
When an MCP server asks for a wider OAuth scope mid-tool-call, Claude Code now surfaces a re-authentication prompt so you can approve it on the spot. Previously, this situation would often just fail the call or surface a confusing error with no clear cause.
If you’re using an MCP server with tiered permissions — say, one that escalates from read-only to write access — you can now re-authenticate on the spot when a call gets blocked mid-task, instead of having to restart the session. Full release notes
Developer Workflow Tips
Stick to the explore → plan → implement → verify order
A roundup of Claude Code practices drawn from several production projects argues that the minimum workflow for working safely in production isn’t to let Claude start writing code right away — it’s to have it read the relevant files and explain the current architecture first, draft a plan, implement one clearly-scoped unit of work at a time, verify with diffs and tests, and then write the decisions down.
When you hand off work spanning multiple files — a refactor or a new feature — making Claude go through exploration and planning first, rather than jumping straight to implementation, cuts down on the chance it builds on a wrong assumption. aiorg.dev
Keep CLAUDE.md under 200 lines, and scope each session to one task
A longer CLAUDE.md eats more context and noticeably hurts how well instructions get followed, so the recommendation is to keep it under 200 lines — and to scope each session to a single task, since a focused context produces better results and makes review easier.
If your project’s CLAUDE.md keeps growing, trim it down to the essentials — architecture, coding standards, key paths, and frequently used commands — and if you’re in the habit of stacking multiple tasks into one session, splitting them up will pay off in the quality of what comes out. Collabnix
Security & Limitations
Claude service status — all operational as of 10/3, two stable days since the 10/1 credit-delay incident (10/3)
Checking status.claude.com directly shows that, as of 10/3, claude.ai, Claude Console, Claude API, Claude Code, Claude Cowork, and Claude for Government are all Operational, with no active incidents. The most recent incident, the 10/1 “Platform Credit Delays” issue, was resolved that same day at 22:36 UTC, and the platform has now run two straight days without incident.
Every incident over the past 90 days — the 9/22 multi-model errors, the 9/29 error spike, and the 10/1 credit delay — was resolved within the day it occurred, so at this point there’s no reason to deviate from the normal path. Claude Status
”I was the target” — an attack attempt used a git post-checkout hook to steal credentials (10/3)
Developer Frank Wiles was targeted by an attack disguised as an edtech web app development inquiry, which tried to run arbitrary code on his laptop — apparently aimed at his GitHub account or client-related access. The attacker asked him to review project materials and sign an NDA before a meeting, then planted a post-checkout hook in a repository shared via Dropbox, designed to run arbitrary code the moment it was checked out.
If you ever check out repositories or sample projects from outside sources while working in Claude Code, it’s worth making a habit of checking the .git/hooks directory before opening anything from a source you don’t fully trust. GeekNews
Apple to tighten macOS Full Disk Access controls (10/3)
Apple plans to introduce additional safeguards so that users fully understand the risk before granting an app Full Disk Access. The permission is necessary for backup apps to function properly, but it’s also a powerful one that bypasses much of macOS’s privacy protections.
If you’ve granted Claude Desktop or your own agent Full Disk Access on macOS, it’s worth keeping an eye on this change — once the new controls land, you may need to re-approve the permission or go through extra confirmation steps. GeekNews
Ecosystem & Plugins
Supabase announces Turso acquisition — consolidating database infrastructure for AI-agent-built apps (10/3)
Supabase has announced it’s acquiring Turso, combining forces to build the database infrastructure needed for the flood of apps and prototypes that AI agents are now churning out. Supabase already creates over a million databases a week, and the goal is to make databases as light and cheap to spin up as files, rather than provisioning a dedicated server for every small task.
For teams cranking out prototypes with agents like Claude Code, this could make it easier to attach a lightweight database to every agent-generated app without standing up a heavy DB server each time. GeekNews
Community News
- Giving Opus 5.5 a virtual canvas and letting it paint (10/3): stillwet’s experiment has Opus 5.5 writing brushstrokes as code to paint an oil painting, with no image-generation model involved. A virtual studio simulates the brush, wet paint, drying, and layering, and the model paints a little at a time, checking the canvas before deciding its next stroke. GeekNews
- OpenAI announces ChatGPT Sites (10/3): Describe what you want in conversation, and ChatGPT builds, hosts, and lets you share websites, apps, and games — all from within the chat. It starts from an existing Codex project, lets you test it in an in-app browser, and you can keep refining it through conversation. It’s a direct challenge to Claude’s Artifacts, and shows the competition over conversational app builders is only heating up. GeekNews
Minor Changes
All of the following are from v2.1.288 (10/2).
- Prompts cleared with Ctrl+C can now be restored with the Up arrow — pasted text and images come back intact too.
- Added Ctrl+F session search and Alt+↑/↓ group navigation to the agent view. Both can be rebound in keybindings.json, along with the renaming shortcut.
claude project purgehas been renamed toclaude purge. The old name still works and now shows a notice./autocompactnow stores settings per model, so switching models keeps each one’s own configuration.- The URL prompt for MCP servers that can’t report completion now waits for an “I’m done, continue” input, so you can finish the flow in the browser first and then resume tool calls.
- Background command timeouts now only apply to non-interactive sessions (
-p, the Agent SDK, CI, cloud) — terminal, desktop app, and VSCode sessions have no timeout.
Recommended Reads
- The four horsemen of agentic coding (10/3): Agentic coding is enormously useful, but this piece argues it brings four problems — slop, alienation, skill atrophy, and weakened team relationships — that exact a real toll on developers’ curiosity, craftsmanship, and social connection. The core complaint: the particular style of LLM-generated code makes it harder for people to read and get familiar with a codebase. GeekNews
- AI makes me sad (10/3): A candid admission that even though AI might land you a good job, the writer doesn’t want a career spent just directing agents instead of building code themselves. Their dream of starting a company on the strength of their own development skills wavers against the thought that someone else could clone it with a 30-second prompt. It’s a personal take on the same alienation the “four horsemen” column above describes. GeekNews
- Linux kernel developer Greg Kroah-Hartman on security in the LLM era [video] (10/3): His talk argues that verifying and fixing real bugs matters more than the raw number of vulnerabilities an LLM claims to have found. He points to cases where many “tool-discovered” Linux vulnerabilities turned out to be false positives, duplicates, or issues already fixed — a warning against taking AI security tools’ output at face value just because of the numbers. GeekNews
Interesting Projects & Tools
- Show GN: ALPS Writer and ADR Writer — spec and design-decision management plugins for Claude Code and Codex (10/3): An open-source plugin bundle pairing ALPS Writer, which builds product requirement documents (PRDs) through Q&A, with ADR Writer, which records design decisions. Both support a full format and a Lite format that trims things down to four sections for small proofs of concept. It’s released under the MIT license, so you can drop it straight into a Claude Code or Codex workflow. GeekNews
- Audionaut — an open-source multitrack audio editor built for AI-agent editing (10/3): A free, open-source audio editor for music, podcasts, and multitrack recordings that skips the complexity of full music production software and focuses on cutting and arranging the parts you need. It hands off editing to AI agents like Claude over MCP, and lets you inspect changes and undo each edit individually within an open project. GeekNews