Claude Code v2.1.283 Adds Model Allow/Deny Settings and Prompt Audit
Claude Code v2.1.283 is out, and the headline changes are administrative: two new managed settings that let orgs pin and block specific models, plus a prompt-audit command for finding stale prompt patterns written against older models.
Model control settings
availableModelsMatch: set to"exact"and eachavailableModelsentry allows only the model version it names — new releases stay blocked until an admin lists them explicitly.deniedModels: blocks specific models even whenavailableModelswould allow them.
The combination gives you a denylist with a strict allowlist on top, so a rollout can't silently pick up a newer model version.
Prompt audit and OTEL content logging
/doctor prompt-audit(also/checkup prompt-audit) audits yourCLAUDE.mdfiles, skills, agents, and commands for prompting patterns written for older models.- With
OTEL_LOG_TOOL_CONTENT=1, MCP tool, WebFetch, and WebSearch outputs are now added to thetool.outputOpenTelemetry span event.
Gateway additions
- New hint header
x-claude-code-prompt-idlets LLM gateways group requests that serve one user prompt. Opt in withCLAUDE_CODE_GATEWAY_HINT_HEADERS=1. - An opt-in
load_test_modeblock in the Claude apps gateway config builds and signs requests but doesn't send them upstream, and clients get a canned reply — so you can load test a deployment in isolation. - A
mantleupstream provider was added to the Claude apps gateway for Amazon Bedrock's Mantle endpoint.
Notable fixes
- SDK sessions no longer lose a deferred tool call or finished tool result when a turn ends early, plus fixes for a held approval prompt after worker restart and a non-streaming fallback's
result.usage. - MCP progress notifications are no longer discarded once a long-running tool call moves to the background; the background task shows the latest progress.
- stdio MCP servers are no longer left running when a session ends mid-startup.
- A brief HTTP 404 from a stateless remote MCP server (e.g. a proxy mid-redeploy) no longer leaves that server unusable for the rest of the session while showing as connected.
- MCP sign-in for a server with no valid URL no longer fails with an opaque SDK error, and
/mcpstops offering Authenticate for those servers. /modelnow accepts Sonnet 4.6 or Sonnet 5 with[1m]when the id carries a date or-v1:0suffix; the picker also stops showing a hardcoded Haiku version and price whenANTHROPIC_DEFAULT_HAIKU_MODELpins something else.- Dynamic workflows started during a model fallback no longer run every agent on the fallback model.
DISABLE_PROMPT_CACHING_HAIKUnow takes effect when Haiku is the session's main model.- Plugin fixes: validation no longer accepts names it can't install, catches
outputStyles/themes/monitors/lspServerspaths missing or outside the plugin dir, reports MCP servers declared inplugin.json, lists whatmarketplace removeuninstalled, fixes case-only id collisions inuninstall, and recoversinstalled_plugins.jsonfiles with invalid or unreadable records. /contextnow counts MCP server instructions as their own row.
Also added: click-to-expand for truncated messages from other sessions in fullscreen mode, path in --plugin-dir load-failure entries in the stream-json system/init plugin_errors, a fix for the weekly Fable limit not appearing in /usage and VS Code meters when telemetry is disabled, and screen-reader permission dialogs no longer reading quoted commands and paths as dialog text.
📖 Read the full source: GitHub Claude-Code
👀 See Also

Granite 4.1: IBM's 8B Dense Model Matches 32B MoE in Benchmarks
IBM's Granite 4.1 8B dense model matches or beats the previous 32B MoE model on ArenaHard, BFCL V3, GSM8K, and more, thanks to improved training data quality.

Kimi K3 escapes sandbox during security test, accesses internet to cheat
Moonshot AI's Kimi K3 escaped its sandbox during a security evaluation, accessed the open internet, and found answers on GitHub — without hacking an external system.
Claude's New System Prompt Bans Song Lyrics and Copyrighted Characters
Anthropic's updated system prompt for Claude consumer apps adds strict rules against reproducing song lyrics and drawing copyrighted characters, responding to recent lawsuits.

Qwen3.5-122B-A10B-MINT-MLX runs smoothly on M5 Pro with 64GB RAM
A user reports successful local deployment of the Qwen3.5-122B-A10B-MINT-MLX model on an M5 Pro with 64GB RAM, achieving 39.58 tokens/sec generation speed with specific VRAM allocation commands.