Claude Code 2.1.187 blocks sandboxed credentials
Anthropic has released Claude Code 2.1.187, introducing a new security setting to block sandboxed commands from reading credentials and secret environment variables. The update also adds organization-configured model restrictions and a five-minute timeout on remote MCP tool calls to prevent freezes.
Securing environment variables and credentials from autonomous agent execution is becoming a critical security standard. This release shows Anthropic prioritizing enterprise compliance and robustness over raw features.
- –The sandbox.credentials setting mitigates risks of malicious packages or generated scripts leaking sensitive local credentials.
- –Org-configured model restrictions provide administrators with fine-grained control over model usage and spending policies in developer terminals.
- –The 5-minute timeout on remote MCP tools resolves a common pain point where unresponsive external APIs hung user CLI sessions indefinitely.
- –The rapid release cycle, coming just one day after version 2.1.186, demonstrates quick iteration based on developer feedback.
DISCOVERED
1h ago
2026-06-23
PUBLISHED
1h ago
2026-06-23
RELEVANCE
AUTHOR
ClaudeCodeLog