diff --git a/CHANGELOG.md b/CHANGELOG.md
index 7ca26b54c..389a1ae97 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -1,5 +1,47 @@
# Changelog
+## 2.1.221
+
+- [VSCode] Added Focus view: a chat-menu toggle that hides tool activity behind an expandable per-turn summary with a live running-tool indicator, toggled with `Ctrl+Alt+F` or the "Claude Code: Toggle Focus view" command
+- Added `mode: "mask"` for sandbox credential files on Linux and WSL — sandboxed commands read a sentinel copy (the whole file, or just the spans captured by an `extract` regex) while the sandbox proxy substitutes the real value on egress; on macOS file masking falls back to `deny`
+- Added warnings to `claude plugin validate` when a marketplace or plugin name would be rejected by Claude Desktop's managed marketplace sync
+- Added a `prompt-audit` subcommand to the `claude-api` skill for auditing prompts and tool descriptions for patterns written for older models
+- Fixed a Bash tool permission-check bypass where zsh could execute hidden commands in `[[ ]]` regex conditionals; affected commands now prompt for permission
+- Fixed PowerShell permission checks mishandling paths containing quote characters on Windows; such paths now prompt for approval
+- Fixed the thinking toggle having no effect for the rest of a session that started with thinking off; disabling an MCP server mid-connect no longer silently reverts
+- Fixed MCP servers from `--mcp-config` not being connected before the first turn in print mode (`-p`), which made the model emit tool calls as literal text
+- Fixed @-mentioned files being silently dropped when pressing Esc to retract a prompt and resubmitting it
+- Fixed a crash when preparing API requests for SDK MCP tools named after built-in object properties such as `constructor`
+- Fixed WebSearch failing with a 400 error at effort `xhigh`/`max` when thinking is disabled
+- Fixed sandboxed large uploads failing with TLS errors through the sandbox proxy
+- Fixed Team and Enterprise spend-limit message incorrectly blaming the org's monthly limit instead of your individual spend limit
+- Fixed Bedrock authentication with AWS SSO named profiles failing in desktop-managed sessions on Windows machines that set a stray `HOME` environment variable
+- Fixed `CLAUDE_CODE_RESUME_INTERRUPTED_TURN=0` not disabling interrupted-turn auto-resume; falsy values are now honored
+- Fixed a rare wake-from-sleep race where two Claude Code processes could both refresh the same MCP connector or WIF OAuth token at once, forcing re-authentication
+- Fixed renaming a session from Claude Code Desktop or claude.ai not updating the CLI's session name; session names from every rename surface are now sanitized
+- Fixed plugin- and org-delivered skills named after terminal-only built-ins (e.g. `/help`, `/feedback`) being un-invocable in non-interactive sessions
+- Fixed the "Plugins changed" notification lingering after plugins were reloaded instead of clearing
+- Fixed Vim mode: the yank register now survives dialogs, history search, and the transcript view instead of being silently emptied
+- Fixed Vim mode: undoing back to an empty prompt now arms the "press ← again" confirm before returning to the agent view
+- Improved tool search on Google Vertex AI: re-enabled for Claude 4.5-generation and newer models
+- Improved auto mode: permission checks for parallel tool calls are now cache-efficient, and switching modes while a check is pending reliably prompts instead of applying the stale result
+- Reduced prompt-cache costs for auto-mode permission checks by reusing the cached conversation prefix across decisions
+- Improved Stats panel to count cache tokens in its token totals, with a breakdown by input, output, cache read, and cache write
+- Improved `/ultrareview` error messages when a repo shares no history with its base: a checkout with no branches is now refused up front with advice to create one, and refusal hints no longer suggest `git fetch --unshallow` on clones that are already complete
+- Improved Windows startup: process creation times are now read via a native kernel32 call instead of spawning PowerShell, so endpoint security tools that gate `powershell.exe` no longer prompt
+- Changed background sessions to commit and push to preserve work, open a draft PR only when the task calls for one, follow your CLAUDE.md git instructions, and always end by reporting where the work lives
+- Changed `/plugin install` to refresh a stale marketplace catalog and retry before reporting a plugin not found
+- Changed plugins installed from `/plugin` to activate immediately when safe, instead of always requiring `/reload-plugins`
+- Changed plugins to accept `"."` as a `skills` path, and the root-level `SKILL.md` validation error now suggests using the plugin root
+- Changed `/status` to show the session kind: `interactive`, or a background job that is `attached` or `unattended`
+- Changed emoji autocomplete to accept common alternate shortcodes like `:thumbsup:`, `:thumbsdown:`, and `:love:`
+- Changed sessions forked with `/fork` to create a new worktree of their own instead of working in the original session's checkout
+- Changed Claude in Chrome to close the browser tabs it opens once it no longer needs them
+- Changed fast mode to report on the stream when usage credits run out mid-session, instead of failing silently
+- Changed Monitor: a watch that exits without producing any output now says so instead of reporting "stream ended"
+- Changed the Gateway `model` field validation: non-string values are rejected with a 400 instead of being forwarded
+- Removed the repeated "Permission mode changed while the auto-mode classifier call was queued" notice from approval prompts
+
## 2.1.220
- Bug fixes and reliability improvements
diff --git a/feed.xml b/feed.xml
index 154191677..d6f9c05c5 100644
--- a/feed.xml
+++ b/feed.xml
@@ -6,7 +6,52 @@
Anthropic
- 2026-07-25T01:35:47Z
+ 2026-08-04T00:14:17Z
+
+ https://github.com/anthropics/claude-code/releases/tag/v2.1.221
+ Claude Code v2.1.221
+
+ 2026-08-04T00:14:17Z
+ <p>• [VSCode] Added Focus view: a chat-menu toggle that hides tool activity behind an expandable per-turn summary with a live running-tool indicator, toggled with Ctrl+Alt+F or the "Claude Code: Toggle Focus view" command</p>
+<p>• Added mode: "mask" for sandbox credential files on Linux and WSL — sandboxed commands read a sentinel copy (the whole file, or just the spans captured by an extract regex) while the sandbox proxy substitutes the real value on egress; on macOS file masking falls back to deny</p>
+<p>• Added warnings to claude plugin validate when a marketplace or plugin name would be rejected by Claude Desktop's managed marketplace sync</p>
+<p>• Added a prompt-audit subcommand to the claude-api skill for auditing prompts and tool descriptions for patterns written for older models</p>
+<p>• Fixed a Bash tool permission-check bypass where zsh could execute hidden commands in [[ ]] regex conditionals; affected commands now prompt for permission</p>
+<p>• Fixed PowerShell permission checks mishandling paths containing quote characters on Windows; such paths now prompt for approval</p>
+<p>• Fixed the thinking toggle having no effect for the rest of a session that started with thinking off; disabling an MCP server mid-connect no longer silently reverts</p>
+<p>• Fixed MCP servers from --mcp-config not being connected before the first turn in print mode (-p), which made the model emit tool calls as literal text</p>
+<p>• Fixed @-mentioned files being silently dropped when pressing Esc to retract a prompt and resubmitting it</p>
+<p>• Fixed a crash when preparing API requests for SDK MCP tools named after built-in object properties such as constructor</p>
+<p>• Fixed WebSearch failing with a 400 error at effort xhigh/max when thinking is disabled</p>
+<p>• Fixed sandboxed large uploads failing with TLS errors through the sandbox proxy</p>
+<p>• Fixed Team and Enterprise spend-limit message incorrectly blaming the org's monthly limit instead of your individual spend limit</p>
+<p>• Fixed Bedrock authentication with AWS SSO named profiles failing in desktop-managed sessions on Windows machines that set a stray HOME environment variable</p>
+<p>• Fixed CLAUDE_CODE_RESUME_INTERRUPTED_TURN=0 not disabling interrupted-turn auto-resume; falsy values are now honored</p>
+<p>• Fixed a rare wake-from-sleep race where two Claude Code processes could both refresh the same MCP connector or WIF OAuth token at once, forcing re-authentication</p>
+<p>• Fixed renaming a session from Claude Code Desktop or claude.ai not updating the CLI's session name; session names from every rename surface are now sanitized</p>
+<p>• Fixed plugin- and org-delivered skills named after terminal-only built-ins (e.g. /help, /feedback) being un-invocable in non-interactive sessions</p>
+<p>• Fixed the "Plugins changed" notification lingering after plugins were reloaded instead of clearing</p>
+<p>• Fixed Vim mode: the yank register now survives dialogs, history search, and the transcript view instead of being silently emptied</p>
+<p>• Fixed Vim mode: undoing back to an empty prompt now arms the "press ← again" confirm before returning to the agent view</p>
+<p>• Improved tool search on Google Vertex AI: re-enabled for Claude 4.5-generation and newer models</p>
+<p>• Improved auto mode: permission checks for parallel tool calls are now cache-efficient, and switching modes while a check is pending reliably prompts instead of applying the stale result</p>
+<p>• Reduced prompt-cache costs for auto-mode permission checks by reusing the cached conversation prefix across decisions</p>
+<p>• Improved Stats panel to count cache tokens in its token totals, with a breakdown by input, output, cache read, and cache write</p>
+<p>• Improved /ultrareview error messages when a repo shares no history with its base: a checkout with no branches is now refused up front with advice to create one, and refusal hints no longer suggest git fetch --unshallow on clones that are already complete</p>
+<p>• Improved Windows startup: process creation times are now read via a native kernel32 call instead of spawning PowerShell, so endpoint security tools that gate powershell.exe no longer prompt</p>
+<p>• Changed background sessions to commit and push to preserve work, open a draft PR only when the task calls for one, follow your CLAUDE.md git instructions, and always end by reporting where the work lives</p>
+<p>• Changed /plugin install to refresh a stale marketplace catalog and retry before reporting a plugin not found</p>
+<p>• Changed plugins installed from /plugin to activate immediately when safe, instead of always requiring /reload-plugins</p>
+<p>• Changed plugins to accept "." as a skills path, and the root-level SKILL.md validation error now suggests using the plugin root</p>
+<p>• Changed /status to show the session kind: interactive, or a background job that is attached or unattended</p>
+<p>• Changed emoji autocomplete to accept common alternate shortcodes like :thumbsup:, :thumbsdown:, and :love:</p>
+<p>• Changed sessions forked with /fork to create a new worktree of their own instead of working in the original session's checkout</p>
+<p>• Changed Claude in Chrome to close the browser tabs it opens once it no longer needs them</p>
+<p>• Changed fast mode to report on the stream when usage credits run out mid-session, instead of failing silently</p>
+<p>• Changed Monitor: a watch that exits without producing any output now says so instead of reporting "stream ended"</p>
+<p>• Changed the Gateway model field validation: non-string values are rejected with a 400 instead of being forwarded</p>
+<p>• Removed the repeated "Permission mode changed while the auto-mode classifier call was queued" notice from approval prompts</p>
+ https://github.com/anthropics/claude-code/releases/tag/v2.1.220Claude Code v2.1.220
@@ -586,27 +631,4 @@
2026-07-03T23:50:29Z<p>• Claude Sonnet 5 sessions no longer use the mid-conversation system role for harness reminders</p>
-
- https://github.com/anthropics/claude-code/releases/tag/v2.1.200
- Claude Code v2.1.200
-
- 2026-07-03T16:52:26Z
- <p>• Changed AskUserQuestion dialogs to no longer auto-continue by default; opt into an idle timeout via /config</p>
-<p>• Changed the "default" permission mode to "Manual" across the CLI, --help, VS Code, and JetBrains; --permission-mode manual and "defaultMode": "manual" are accepted alongside default</p>
-<p>• Fixed a crash at startup when disabledMcpServers or enabledMcpServers in .claude.json is set to a non-array value</p>
-<p>• Fixed background sessions silently stopping mid-turn after sleep/wake or when reopening a stalled session</p>
-<p>• Fixed background sessions re-running a turn cancelled with Esc after a stall respawn</p>
-<p>• Fixed background agents never starting again after a crash left a stale daemon.lock whose PID the OS reused</p>
-<p>• Fixed background-agent daemon handover so a reinstalled older build can no longer take over the daemon; build recency is now judged by the version's embedded build timestamp</p>
-<p>• Fixed background-agent roster issues: transient corruption permanently disabling orphan cleanup, older binaries not preserving fields written by newer versions, and socket auth tokens being stripped during daemon restarts</p>
-<p>• Fixed subagents cut off by a rate limit before producing any text output returning an empty result instead of failing cleanly</p>
-<p>• Fixed control bytes from background-agent output reaching the terminal in the agent view</p>
-<p>• Fixed claude agents --plugin-dir <dir> not showing the plugin's agents and skills in the agent view when the flag is placed after agents</p>
-<p>• Fixed project-scoped plugins not loading correctly from git worktrees of the same repository</p>
-<p>• Fixed /mcp server list not tracking focus for screen readers and magnifiers</p>
-<p>• Fixed voice dictation showing a misleading "Voice connection failed" message when a recording captures no audio</p>
-<p>• Fixed rendering flicker under tmux 3.4+ by enabling synchronized terminal output</p>
-<p>• Improved screen-reader output: decorative glyphs are now hidden, transcript symbols read as short labels, and nested tables read as Header: value. lines</p>
-<p>• Improved the install script to explain when installation is killed by the system running out of memory</p>
-