Claude Code 2.1.290 Adds Advisor Data and Clearer Plugin Hook Validation
Claude Code v2.1.290 adds advisor tool records, identifies subagent permission checks, exposes required-approval metadata, and reports gating hooks with .catch handlers.
Anthropic has shipped Claude Code v2.1.290 and a fast-follow v2.1.291 patch. For mod and plugin developers, v2.1.290 adds records of server-side advisor tool calls, identifies subagent permission checks, and exposes the approval an organization requires for a tool. The CLI also reports which gating hooks define a .catch handler. These additions give developers more information for inspecting tool activity and implementing their own policies. Teams still need to test their policy logic and error-handling behavior before deployment.
The serverToolUses field is new in the result of a mod’s turn.step hook. It supplies records of tool calls that the API ran itself through the advisor, with id, name, input, start, and end fields. The release notes name start and end without specifying their data format. Mods can use the exposed records to inspect advisor activity alongside local tool activity. The Context Engineering Playbook provides related guidance on tracking the context and actions used by coding agents.
Subagent Awareness and Organization Ceilings
Claude Code v2.1.290 adds agentId to the tool.check event for plugin hooks. The release notes describe this as a way for a hook to distinguish a subagent’s permission check from the main session’s. A developer can use that information as input to custom hook logic, such as applying different checks to child agents, then test the resulting policy decisions. For teams following Subagent Orchestration: Fleet Patterns for Daily Drivers, the field provides a concrete way to attribute permission checks within an agent hierarchy.
The question and verdict read by a mod’s tool.check hook also gain a ceiling property. The release notes describe it as naming the approval an organization requires for a tool. Developers can inspect that required-approval metadata while building their hook logic. The exposed field provides information about the requirement; implementing and testing a policy remains a separate responsibility.
Plugin Validation and Gateway Controls
The claude plugin validate command now lists each hook a mod registers at a gating site and reports whether it has a .catch handler. The JSON output includes this information under gatingHooks. This is a handler-presence check; checking how a handler behaves requires separate tests. Operators can incorporate the inventory into their Claude Code Mods Are In-Process Code: Keep an Extension Manifest for Every Machine procedures, then exercise exception paths before relying on a hook in a managed environment.
In the realm of access control, the Claude apps gateway sign-in approval page has gained a long-overdue “Deny” button. Clicking it ends the pending sign-in, so the waiting terminal stops within seconds. This improves the operator experience when securing managed environments.
The update also brings ThemeKey and Color types to the plugin hooks typings, enabling better editor support for mods that render custom UI elements directly in the terminal.
Session Management and Fixes
Beyond policy hooks, v2.1.290 includes several quality-of-life improvements for session management. Operators can now use claude attach <name> and claude logs <name>, relying on a partial session name instead of copying the session ID. For teams setting up managed environments, the CLI adds /claude-api managed-agents-onboard <url> to set up the Managed Agents pattern described by ant apply files, and a variant for Console quickstart templates like deep-researcher with the Ant CLI.
The release also patches a number of notable bugs. Most notably, v2.1.290 fixes a bug where a PreToolUse hook could rewrite a tool call’s input, causing subsequent permission rules to be skipped. It also fixes an issue on macOS and Windows where an image read could return an unapproved file via a link swapped mid-read, and tightens the auto-mode classifier in plan mode, which previously could incorrectly approve non-read-only connector tools that carried a server-pushed ask policy.
Other fixes include addressing a crash when a response nested lists or quotes thousands of levels deep. Furthermore, the update fixes a bug where a project CLAUDE.md, rule, or AGENTS.md symlinked outside the working directories could mistakenly load despite permissions.blockReadsOutsideWorkingDirectories or a Read deny rule being active.
The v2.1.291 patch, released shortly after, repairs two important regressions. It fixes an issue in v2.1.290 where cloud sessions could drop answers to permission prompts, and resolves a v2.1.288 bug where the last messages of a session could be lost when quitting. You can verify these updates on the official Claude Code CHANGELOG.
Here is the official release shot from the Claude Code repository:

Practical Significance for Operators
Fleet administrators evaluating these changes should include the v2.1.291 cloud-session permission-answer and final-message fixes in their rollout checks. Our subsequent Claude Code v2.1.292 report covers the newer release. Select a current release that passes your team’s tests in the target environment, including cloud sessions, plugin hooks, and installed mods. Verify that permission-prompt answers are retained and that final messages remain available when a session closes before expanding the rollout.
For teams maintaining internal mods, the new fields provide specific integration points to review. Update turn.step consumers to inspect serverToolUses records and decide which advisor-call data to log. Run claude plugin validate --json to inventory gating hooks and .catch presence, then test the handlers’ behavior separately. For workflows using subagents, review how tool.check logic consumes agentId and the ceiling required-approval metadata. These checks help teams understand their custom policy implementation before rolling it out.
The discussion in Deadbugz Killed Approve-Once explains why runtime controls matter in agent workflows. Claude Code 2.1.290 adds advisor-call records and approval-related hook metadata that can support operator inspection and custom policy logic. Teams adopting these fields should pair the documented metadata with behavior tests of their own hooks and keep their extension inventory current.