RepoJournal

$ cat anthropics/month/2026-09-01.log

Anthropic

Anthropic

the month in review · September 2026

Sandbox and SDK holes dominate Anthropic's September

By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology

♥

Three command-execution and file-read flaws shipped fixes across the Python agent SDK, Claude Desktop for macOS, and buffa's JSON parser.

436 commits 443 PRs merged 51 releases 3 security advisories 30 briefings covered

all anthropics reviews →

Argument Injection via resume Option Allows Arbitrary Command Execution anthropics/claude-agent-sdk-python

Passing a crafted value through the resume option let an attacker run arbitrary commands, an argument injection rather than a parser bug. If you accept resume identifiers from anything a user or upstream service controls, pin the patched SDK release before shipping.

Claude Desktop (macOS): opening a malicious file from a Cowork folder could run commands on the host anthropics/claude-code

Opening a malicious file from a Cowork folder on macOS could execute commands on the host, so the trust boundary is the file's contents, not the folder. Teams running Claude Desktop on macOS should update rather than rely on folder scoping as isolation.

v2.1.284 anthropics/claude-code

by ashwin-ant

Claude Sonnet 5.5 (claude-sonnet-5-5) is now the default Sonnet model on the Anthropic API: 1M context, $2/$10 per Mtok, with cache reads at $0.20 per Mtok. Auto mode also gained a "Yes, but ask again next time" answer for reads outside the working directories, which changes how often you are re-prompted.

v2.1.277 anthropics/claude-code

by ashwin-ant

In a project with no CLAUDE.md, Claude Code now reads AGENTS.md, switchable under "Project instructions" in /config, the release notes say. It is not yet available on Bedrock, Vertex or Foundry, so make that the deciding factor before you migrate a repo's instruction file.

v0.47.0 anthropics/anthropic-sdk-php

by stainless-app[bot]

Usage reports gain Claude Tag category and user breakdowns, mirrored the same day in the Java SDK at 2.61.0 and, on the CLI side, named types for organization compliance settings state. Cost attribution per tag is now something you can read straight off the API rather than reconstruct.

axt-verify v0.1.0 anthropics/axt-verify

by eperrine-ant

The first tagged release of the command-line verifier for the Anthropic Access Transparency log, installable with go install at v0.1.0 and requiring Go 1.26 or newer. The README is explicit about what it checks and what it cannot, which is worth reading before you put it in an evidence path.

docs(changelog): detail the beta files/skills GA-shape change anthropics/anthropic-sdk-go

by tomer-ant

The Python and Go changelogs now spell out the beta files/skills GA-shape change, including what moved in the beta namespaces and links to migration guides. In short: beta files and skills namespaces use GA shapes and drop dated beta header pins, so update pinned headers as you rebuild against the new SDKs.

$ ls anthropics/month/ # the briefings behind this review

Tue Sep 1 buffa fixes double-drop, unset ProtoJSON null, and re-measures benchmarks Wed Sep 2 Buffa bounds Any nesting; Claude Security Plugin v0.11.0 lands Thu Sep 3 Buffa descriptor pool now rejects malformed enums and reserved fields Fri Sep 4 Claude Code bumps to 2.1.260 across action and SDK Sat Sep 5 SDKs ship compliance types, Claude Tag usage breakdowns Sun Sep 6 Claude Code 2.1.263 ships across GitHub Actions and SDK packages Mon Sep 7 Buffa strict parsers: unknown fields and bad descriptor indices now rejected Tue Sep 8 Homebrew tap ships ant v1.31.0 cask updates Wed Sep 9 Claude Code and Agent SDK sync to 2.1.266 across action repos Thu Sep 10 Claude Code ships hooks-module plugins as source, security-guidance learns repo resolution Fri Sep 11 sandbox-runtime blocks DNS-resolved private IPs, buffa stops double-writing bytes Sat Sep 12 NetSuite plugins land in Cowork, wealth-management plugin pulled Sun Sep 13 Argument injection in claude-agent-sdk-python, mod test harness lands in claude-code Mon Sep 14 Mod tests move next to their mods, BlackRock Advisor Center lands twice Tue Sep 15 A root write/read root no longer disables sandbox denies, npm root lookup off the event loop Wed Sep 16 Diff pane stops surprising you, sales plugin goes 9 to 36 skills Thu Sep 17 Sales plugin declares Salesforce and Microsoft 365 connectors, plugin directory adds six integrations Fri Sep 18 Sandbox-runtime closes a silent deny-glob hole and two Linux startup failures Sat Sep 19 Claude Code 2.1.277 reads AGENTS.md, agent-sdk ships the AGENTS.md mod Sun Sep 20 Verbatim prompt mode closes an @-path file read in the Python SDK Mon Sep 21 Buffa hardens WKT and descriptor parsing, claude-code smooths the diff pane Tue Sep 22 Explicit string copying lands in buffa 0.10 Wed Sep 23 Buffa closes silent JSON parse failures, quickstarts move to ant apply Thu Sep 24 Codegen lifetime bug in buffa views, descriptor pool tightens validation Fri Sep 25 Gateway stops trusting stale signing keys, tokio publishes to internal registry Sat Sep 26 Cowork folder file execution on macOS, axt-verify v0.1.0 Sun Sep 27 buffa closes a JSON recursion bypass, shrinks generated encoders Mon Sep 28 Scope guard stops failing command-source PRs Tue Sep 29 Sonnet 5.5 becomes the default, Opus 5.5 takes over the skills docs Wed Sep 30 Claude CI moves behind the egress firewall, permission mode goes auto"

Keep up with Anthropic in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

all anthropics reviews →