version-check — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited version-check (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
The goal is a recommendation: stay put, update, or pin to a specific version. Claude Code ships latest very frequently (often 1-2x/day), so "best version" is a moving target and the answer is usually a range, not a single build.
stable dist-tag is just a pointer that trails latest by a handful of patch releases. It can even sit behind an important fix release, so "stable" does not mean "most bugs fixed." Don't blindly recommend @stable.latest constantly, which is how you drift onto a same-day regression.claude --version
npm view @anthropic-ai/claude-code dist-tags --jsondist-tags shows latest, stable, and next. Compare against the installed version to see how far ahead/behind each pointer is.
Recent releases and their timestamps (to see how fast things are shipping):
npm view @anthropic-ai/claude-code time --json | python3 -c "import sys,json;d=json.load(sys.stdin);print('\n'.join(f'{k}: {v}' for k,v in list(d.items())[-8:]))"Fetch the changelog and read the entries between the installed version and latest. Look for "Fixed ... regression in X" lines - if a recent build introduced a regression that has not yet been fixed, that's the one to avoid.
curl -sL https://raw.githubusercontent.com/anthropics/claude-code/main/CHANGELOG.md | awk '/## <LATEST>/,/## <INSTALLED>/'(Substitute the two version numbers.) A release that is mostly "Fixed …" after a noisy one is usually a safe landing spot.
The most dependable signal. Search recent open bug reports, sorted by reactions, via gh api in a safeclaw container. A version regression shows up as a cluster of high-reaction issues filed right after a release.
docker exec safeclaw-<name> bash -c 'gh api -X GET search/issues \
-f q="repo:anthropics/claude-code is:issue is:open created:>=<DATE> label:bug" \
-f sort=reactions -f per_page=25 \
--jq ".items[] | \"\(.created_at[:10]) +\(.reactions.total_count) c\(.comments) #\(.number) \(.title)\""'(Set <DATE> to ~3 days before today.) Cross-reference titles against the changelog gap: if a top issue is already addressed by a fix/flag in latest, that build is safer, not riskier. Mostly minor or server-side (API 500/529) issues = quiet release = good sign.
r/ClaudeAI version-comparison threads are valuable, but Reddit now hard-blocks every direct automated route - curl (host + container), the WebSearch crawler (denied by user-agent), AND a cold Playwright navigation (network-security challenge page). The reliable way in is the reddit-fetch skill's DuckDuckGo-hop unlock: navigate Playwright to a html.duckduckgo.com/html/?q=site:reddit.com/r/ClaudeAI+... result redirect once, which sets a session cookie, then direct .json navigation works:
https://www.reddit.com/r/ClaudeAI/search.json?q=claude+code+update+broke+OR+regression&restrict_sr=on&sort=new&t=week&limit=25Apply the heuristics above: a positive or quiet recent-update thread is reassuring; a high-score "X is broken" thread names the build to skip.
npm install -g @anthropic-ai/[email protected] to pin/rollback.@stable.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.