
The Claude Code Changelog
Claude Code Plugin Security: Fixing Shell Injection
July 13 · 3 min · Episode 71
0:00-3:42
Streams straight from the publisher. podnod never proxies or re-hosts episode audio.
This episode breaks down the breaking changes in Claude Code 2.1.207, including why raw template strings in custom hooks were removed and how shell-injection attacks can happen through plugin configs.
It also covers the safer migration paths with exec-form arrays and CLAUDE_PLUGIN_OPTION_ environment variables, plus the new decision to ignore local repository config files for plugin resolution.
No links were found in this episode’s notes.