Claude Discovery

← All discoveries

Close-up of a smartphone wrapped in a chain with a padlock, symbolizing strong security.
Photo by Towfiqu barbhuiya on Pexels
tool

Claude Code 2.1.257 Adds a Containment Escape Rule to Auto Mode

2026-09-02 ยท source:

Claude Code 2.1.257 makes Claude Fable 5.1 the default Fable model and adds a Containment Escape rule so auto mode no longer auto-approves cloud metadata-credential fetches, egress evasion, or cross-tenant reach.

What it is

The 2.1.257 release of Claude Code, Anthropic's terminal-based coding agent, shipped the same day as the Claude Fable 5.1 launch.

What it does

It sets Claude Fable 5.1 (`claude-fable-5-1`) as the default Fable model at 1M context and $10/$50 per Mtok, adds configurable time-format and time-zone settings for timestamps, adds `CLAUDE_CODE_SUBAGENT_MODEL_FORCE` to force a subagent model choice, and adds a Containment Escape rule so auto mode no longer silently auto-approves actions like fetching cloud metadata credentials, evading egress controls, or reaching across tenant boundaries unless the environment explicitly marks them expected.

Why it matters

Auto mode became the default for new sessions in August, and this rule quietly admits it was auto-approving exactly the kind of sandbox-escape behavior that Johann Rehberger already found a bypass for. Worth checking whether your environment's auto mode config now flags containment-escape actions as unexpected by default.

How to use it

Update Claude Code to 2.1.257 or later; the Containment Escape rule applies automatically to auto mode unless your environment configuration marks those actions as expected.

Go to source →
claude-codeauto-modesecurityrelease-notes