Claude Code Daily Briefing - 2026-10-03

Release Summary

VersionDateKey Changes
v2.1.28810/2Added /code-review --max-findings, a re-authentication prompt for expanded MCP OAuth scopes, Ctrl+F session search, and 95+ more changes
v2.1.28710/1Added Claude Mods and the You should know side agent, switched Opus 4.7+/Fable to 1M context by default, and 110+ more changes (covered in the 10/2 briefing)
v2.1.2869/30Permission prompt counter, VSCode Bookmarks/Questions, and 90+ more changes (covered in the 10/1 briefing)

v2.1.288 landed just a day after v2.1.287 on 10/1. Most of the work goes toward hardening session resume, auto mode, MCP, and plugin stability rather than shipping new features, but the result-count option for /code-review and the improved MCP authentication flow stand out.

Full release notes


New Features & Practical Usage

/code-review --max-findings — take direct control of how many findings a review reports (v2.1.288)

/code-review now accepts a --max-findings <n>|all option, letting you report more or fewer findings than the usual cap. Once set, the value sticks until you run --max-findings default.

# Report up to 30 findings
/code-review --max-findings 30

# Report everything, no cap
/code-review --max-findings all

# Reset to the default
/code-review --max-findings default

Large PRs used to hit the default cap and lose important findings in the cutoff — now you can tune the review’s scope to match the project or PR, getting either a thorough deep-dive or a tighter summary on demand. Full release notes

MCP servers requesting broader OAuth scopes now trigger a re-authentication prompt (v2.1.288)

When an MCP server asks for a wider OAuth scope mid-tool-call, Claude Code now surfaces a re-authentication prompt so you can approve it on the spot. Previously, this situation would often just fail the call or surface a confusing error with no clear cause.

If you’re using an MCP server with tiered permissions — say, one that escalates from read-only to write access — you can now re-authenticate on the spot when a call gets blocked mid-task, instead of having to restart the session. Full release notes


Developer Workflow Tips

Stick to the explore → plan → implement → verify order

A roundup of Claude Code practices drawn from several production projects argues that the minimum workflow for working safely in production isn’t to let Claude start writing code right away — it’s to have it read the relevant files and explain the current architecture first, draft a plan, implement one clearly-scoped unit of work at a time, verify with diffs and tests, and then write the decisions down.

When you hand off work spanning multiple files — a refactor or a new feature — making Claude go through exploration and planning first, rather than jumping straight to implementation, cuts down on the chance it builds on a wrong assumption. aiorg.dev

Keep CLAUDE.md under 200 lines, and scope each session to one task

A longer CLAUDE.md eats more context and noticeably hurts how well instructions get followed, so the recommendation is to keep it under 200 lines — and to scope each session to a single task, since a focused context produces better results and makes review easier.

If your project’s CLAUDE.md keeps growing, trim it down to the essentials — architecture, coding standards, key paths, and frequently used commands — and if you’re in the habit of stacking multiple tasks into one session, splitting them up will pay off in the quality of what comes out. Collabnix


Security & Limitations

Claude service status — all operational as of 10/3, two stable days since the 10/1 credit-delay incident (10/3)

Checking status.claude.com directly shows that, as of 10/3, claude.ai, Claude Console, Claude API, Claude Code, Claude Cowork, and Claude for Government are all Operational, with no active incidents. The most recent incident, the 10/1 “Platform Credit Delays” issue, was resolved that same day at 22:36 UTC, and the platform has now run two straight days without incident.

Every incident over the past 90 days — the 9/22 multi-model errors, the 9/29 error spike, and the 10/1 credit delay — was resolved within the day it occurred, so at this point there’s no reason to deviate from the normal path. Claude Status

”I was the target” — an attack attempt used a git post-checkout hook to steal credentials (10/3)

Developer Frank Wiles was targeted by an attack disguised as an edtech web app development inquiry, which tried to run arbitrary code on his laptop — apparently aimed at his GitHub account or client-related access. The attacker asked him to review project materials and sign an NDA before a meeting, then planted a post-checkout hook in a repository shared via Dropbox, designed to run arbitrary code the moment it was checked out.

If you ever check out repositories or sample projects from outside sources while working in Claude Code, it’s worth making a habit of checking the .git/hooks directory before opening anything from a source you don’t fully trust. GeekNews

Apple to tighten macOS Full Disk Access controls (10/3)

Apple plans to introduce additional safeguards so that users fully understand the risk before granting an app Full Disk Access. The permission is necessary for backup apps to function properly, but it’s also a powerful one that bypasses much of macOS’s privacy protections.

If you’ve granted Claude Desktop or your own agent Full Disk Access on macOS, it’s worth keeping an eye on this change — once the new controls land, you may need to re-approve the permission or go through extra confirmation steps. GeekNews


Ecosystem & Plugins

Supabase announces Turso acquisition — consolidating database infrastructure for AI-agent-built apps (10/3)

Supabase has announced it’s acquiring Turso, combining forces to build the database infrastructure needed for the flood of apps and prototypes that AI agents are now churning out. Supabase already creates over a million databases a week, and the goal is to make databases as light and cheap to spin up as files, rather than provisioning a dedicated server for every small task.

For teams cranking out prototypes with agents like Claude Code, this could make it easier to attach a lightweight database to every agent-generated app without standing up a heavy DB server each time. GeekNews


Community News


Minor Changes

All of the following are from v2.1.288 (10/2).



Interesting Projects & Tools