# Claude Code 2.1.205: transcript-tampering block, Windows worktree data-loss fix

> Adds an auto mode rule blocking tampering with session transcript files and hardens background task notifications against fabricated in-transcript approvals. Also fixes a Windows bug where removing a worktree deleted files outside it through an NTFS junction or directory symlink, and reserves the "Claude Browser" MCP server name so user configs can no longer register under it.

| | |
|---|---|
| **Tool** | Claude Code |
| **Version** | 2.1.205 |
| **Kind** | release |
| **Published** | 2026-07-08 |
| **Observed** | 2026-08-11 |
| **Significance** | 3/5 |
| **Breaking** | yes |
| **Categories** | security, fix, feature, breaking |

## What changed


- New auto mode rule blocks tampering with session transcript files
- Background task notifications now explicitly state that no human input has occurred, preventing fabricated in-transcript approvals from being acted on
- Auto mode now asks before running `rm -rf` on a variable it can't resolve from context
- Fixed Windows worktree removal deleting files outside the worktree when an NTFS junction or directory symlink existed inside it
- Reserved the "Claude Browser" MCP server name (alongside "Claude Preview"); user-configured MCP servers can no longer register under either name
- Fixed `--json-schema` silently producing unstructured output on an invalid schema, and schemas using `format` being rejected
- Fixed a message sent mid-turn being silently lost when the turn ended at the `--max-turns` limit
- Fixed subagents resumed with `SendMessage` still showing "failed"/"completed"; jobs flipping from "needs input" back to "working"; `claude attach` erroring during a mid-upgrade restart
- Fixed session-to-PR linking missing a PR created in a Bash call whose output exceeded the 30K inline limit
- Fixed `claude mcp add-from-claude-desktop` sticking on unsupported characters in a server name; a plugin LSP server failing to initialize blocking another plugin's valid server for the same extension
- Fixed Windows crash when the launch directory is deleted/locked/unmounted mid-command; crash when a file watcher closed during an in-flight directory scan
- Auto-update downloads stream to disk instead of buffering, cutting updater peak memory by ~400 MB
- Agent view rows now show a colored state word and a classifier-written headline instead of raw tool call text; sessions that edit/merge/comment/push to an existing PR link it
- `/doctor` is now a full setup checkup that can diagnose and fix issues; `/checkup` is an alias
- Fixed Cowork VM-mode local-agent sessions failing to start with "Not logged in · Please run /login" on CLI 2.1.203+


## Sources

- [changelog_md](https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md) — retrieved 2026-08-11

## Community

_No curated reactions recorded. Facts and community takes are kept in separate layers
and never blended._

---
Canonical: https://changelogs.info/claude-code/2-1-205
Entity: https://changelogs.info/claude-code
Event ID: `evt_2026-07-08_claude-code_2-1-205`
Licence: event synthesis © changelogs.info, CC BY 4.0. Linked sources belong to their vendors.
