{"collection":{"slug":"coding-agents","name":"Coding Agents"},"digest":{"id":"cwd_IpItXcXmF8yIkyLhGRYb5","weekStart":"2026-07-13","title":"Agents stop acting on their own","intro":"Claude Code stops auto-running verification and review skills, fixes a permission bypass in PowerShell, and redesigns its fork command. Cursor in Slack shares plans before starting work, and Devin simplifies its session sizing model.","body":"### Agents stop running skills without asking\n\nThe week's biggest story is Claude Code shifting from autonomous to explicit. With [v2.1.215](/release/rel_WuIgUSny90synq58Hc-Ol-claude-code-v2-1-215-stops-auto-running-verify-and-code-review-skills), the `/verify` and `/code-review` skills no longer run automatically — Claude will wait for you to invoke them with `/verify` or `/code-review`. This is a meaningful change in the agent's default posture: instead of deciding when to test or review code, it now waits for a direct command. The rationale is clear — these skills can be expensive in both time and tokens, and developers wanted control over when they run.\n\nThe theme of explicit permission continued across the week's releases. [v2.1.214](/release/rel_dUN36wXVsS5wvQiQeWzNG-claude-code-v2-1-214-fixes-permission-bypass-in-powershell-5-1-and-bash) fixed a permission-check bypass in Windows PowerShell 5.1 sessions, plus a fail-open issue in Bash where file-descriptor redirect forms could circumvent the permission analyzer. That same release also added permission prompts for docker daemon-redirect flags, tightened `dir/**` allow rules, and fixed an unbounded memory growth issue with oversized settings files.\n\n### Forks, worktrees, and screen reader support\n\n[v2.1.212](/release/rel_0KZum7utFwb2jPiz2dDy1-claude-code-v2-1-212-redesigns-fork-adds-auto-mode-reset-and-fixes-plan-mode) redesigned `/fork` — it now copies your conversation into a new background session (its own row in `claude agents`) while you keep working in the original. The old in-session subagent has been renamed to `/subtask`. The release also added `claude auto-mode reset` to restore default auto-mode configuration, and fixed a concerning issue where plan mode could auto-run file-modifying Bash commands without a permission prompt or SDK callback.\n\nSecurity work continued with [v2.1.210](/release/rel_jPTMSDTDr3domeEyw4ER7-claude-code-v2-1-210-fixes-worktree-isolation-bypass-and-hardens-security), which fixed worktree isolation: `isolation: 'worktree'` subagents could run git-mutating commands against the main repo checkout instead of their own isolated worktree. That's a real isolation failure that could corrupt the primary branch. The same release also fixed the `ultracode` keyword firing on non-human input.\n\nFor accessibility, [v2.1.208](/release/rel_mUy2O_SXVG9k8bsHpMrwm-claude-code-v2-1-208-adds-screen-reader-mode-and-fixes-memory-leaks) added an opt-in screen reader mode (`claude --ax-screen-reader`) that renders output as plain text. It also fixed multiple memory leaks — MCP stdio server stderr could accumulate up to 64 MB per server, and LSP documents stayed open indefinitely. Earlier in the week, [v2.1.211](/release/rel_gFpV0Wj0HF-k6mGxKVkMs-claude-code-v2-1-211-fixes-permission-preview-spoofing-credential-logout-and) fixed permission previews that could be visually altered by bidirectional-override and look-alike quote characters, plus parallel sessions all logging out after wake-from-sleep and plugin MCP servers not reconnecting after idle.\n\n### Slack plans, ACU-based sizing, and Codex tweaks\n\nCursor in Slack [now shares a plan before starting work](/release/rel_zrkNoXqtxTSx8IVAGXGy3-cursor-in-slack-now-shares-plans-before-starting-and-supports-multi-repo), runs in multi-repo environments, and can work across channels and threads. In-message buttons have been replaced by compact footer links. This makes Cursor's Slack integration feel more like a proper collaborator — you see the plan, redirect early, and follow progress as steps update.\n\nDevin [moved session t-shirt sizes (XS–XL) to be ACU-only](/release/rel_w0VUbKhfaBvpQyye5qGzb-devin-july-15-2026-revamps-session-sizing-to-acu-only-and-adds-text-quoting), no longer factoring in user message count. The release also added text quoting (select text from files, worklog, or Devin's messages and quote it in your next message) and session filtering by skill. Admins can now promote playbooks from a single organization to the entire enterprise.\n\nOn the Codex side, [v0.144.6](/release/rel_PpNiXobP8QeMrUXQcGUid-codex-cli-0-144-6-updates-bundled-instructions-for-gpt-5-6-sol-terra-luna) refreshed bundled instructions for GPT-5.6 Sol, Terra, and Luna, and fixed their context windows to 272,000 tokens. [v0.144.5](/release/rel_yTpBPHUOF62QLIBxqKWtD-codex-cli-0-144-5-expands-dangerous-command-detection-with-more-rm-forms) expanded dangerous-command detection with more forced `rm` forms and clearer rejection reasons.","releaseIds":["rel_WuIgUSny90synq58Hc-Ol","rel_dUN36wXVsS5wvQiQeWzNG","rel_0KZum7utFwb2jPiz2dDy1","rel_jPTMSDTDr3domeEyw4ER7","rel_mUy2O_SXVG9k8bsHpMrwm","rel_gFpV0Wj0HF-k6mGxKVkMs","rel_zrkNoXqtxTSx8IVAGXGy3","rel_w0VUbKhfaBvpQyye5qGzb","rel_PpNiXobP8QeMrUXQcGUid","rel_yTpBPHUOF62QLIBxqKWtD"],"releaseCount":12,"generatedAt":"2026-07-20T06:17:43.431Z","releases":[{"id":"rel_WuIgUSny90synq58Hc-Ol","title":"Claude Code v2.1.215 stops auto-running /verify and /code-review skills","path":"/release/rel_WuIgUSny90synq58Hc-Ol-verify-and-code-review-skills-no-longer-auto-run","org":{"slug":"anthropic","name":"Anthropic"},"importance":4},{"id":"rel_dUN36wXVsS5wvQiQeWzNG","title":"Claude Code v2.1.214 fixes permission bypass in PowerShell 5.1 and Bash redirects","path":"/release/rel_dUN36wXVsS5wvQiQeWzNG-powershell-5-1-permission-bypass-fixed-bash-redirects-fail-closed","org":{"slug":"anthropic","name":"Anthropic"},"importance":4},{"id":"rel_0KZum7utFwb2jPiz2dDy1","title":"Claude Code v2.1.212 redesigns /fork, adds auto-mode reset, and fixes plan mode permission bypass","path":"/release/rel_0KZum7utFwb2jPiz2dDy1-fork-now-copies-conversation-to-background-plan-mode-permission-bypass-fixed","org":{"slug":"anthropic","name":"Anthropic"},"importance":4},{"id":"rel_jPTMSDTDr3domeEyw4ER7","title":"Claude Code v2.1.210 fixes worktree isolation bypass and hardens security","path":"/release/rel_jPTMSDTDr3domeEyw4ER7-worktree-isolation-bypass-fixed-tool-result-hardening","org":{"slug":"anthropic","name":"Anthropic"},"importance":3},{"id":"rel_mUy2O_SXVG9k8bsHpMrwm","title":"Claude Code v2.1.208 adds screen reader mode and fixes memory leaks","path":"/release/rel_mUy2O_SXVG9k8bsHpMrwm-screen-reader-mode-added-memory-leaks-fixed","org":{"slug":"anthropic","name":"Anthropic"},"importance":3},{"id":"rel_gFpV0Wj0HF-k6mGxKVkMs","title":"Claude Code v2.1.211 fixes permission preview spoofing, credential logout, and session cost counter","path":"/release/rel_gFpV0Wj0HF-k6mGxKVkMs-permission-preview-spoofing-fixed-sessions-no-longer-all-log-out-together","org":{"slug":"anthropic","name":"Anthropic"},"importance":3},{"id":"rel_zrkNoXqtxTSx8IVAGXGy3","title":"Cursor in Slack now shares plans before starting and supports multi-repo environments","path":"/release/rel_zrkNoXqtxTSx8IVAGXGy3-slack-integration-shows-plans-upfront-multi-repo-and-cross-channel-support","org":{"slug":"cursor","name":"Cursor"},"importance":3},{"id":"rel_w0VUbKhfaBvpQyye5qGzb","title":"Devin July 15, 2026 revamps session sizing to ACU-only and adds text quoting","path":"/release/rel_w0VUbKhfaBvpQyye5qGzb-session-sizes-now-acu-only-text-quoting-skill-filtering-and-playbook-promotions","org":{"slug":"cognition","name":"Cognition"},"importance":3},{"id":"rel_PpNiXobP8QeMrUXQcGUid","title":"Codex CLI 0.144.6 updates bundled instructions for GPT-5.6 Sol, Terra, Luna","path":"/release/rel_PpNiXobP8QeMrUXQcGUid-gpt-5-6-sol-terra-luna-instructions-and-context-windows-fixed","org":{"slug":"openai","name":"OpenAI"},"importance":2},{"id":"rel_yTpBPHUOF62QLIBxqKWtD","title":"Codex CLI 0.144.5 expands dangerous-command detection with more rm forms","path":"/release/rel_yTpBPHUOF62QLIBxqKWtD-dangerous-command-detection-catches-more-rm-forms","org":{"slug":"openai","name":"OpenAI"},"importance":2}]}}