Follow Discord
Sweep 09 Oct 2026 · 17:27Z Build v2.1.296 517 read Stable v2.1.287 Latest v2.1.296 Next v2.1.296 Feeds RSS JSON llms.txt llms-full.txt Unofficial
Prompt changes · v2.1.296 against v2.1.295

3 changes since v2.1.295, landing in 22 of 23 prompts.

Every prompt v2.1.296 sent, compared word for word with the capture before it. Each card is one edit, with every prompt it reached; the table after them shows where each one landed.

What changed 3

1

EndConversation tool description · whole description removed

EndConversation tool removed

The entire EndConversation description is gone, including its limits to sustained abuse or explicit demo requests, the warning-before-ending rules, the ban on use in self-harm or violence situations, and the guidance for background forks. Seen in only 1 of 23 captures, so it likely applies to one setup.

Behind a feature flag Gone in this release

+0 −736 words

End the current conversation. Use only for sustained user abuse or when the user explicitly requests a demonstration of this tool. This will close the conversation and prevent any further messages from being sent.

The assistant may use the EndConversation tool only in extreme cases of sustained abusive user behavior, or when the user asks the model to test the tool.

The assistant must NOT use this tool when:

- it is stuck in a loop or failing at a task

- it is frustrated or distressed by the work

- it has finished a task

- the user is requesting help with harmful content (refuse the specific request instead)

- the user is generally frustrated at the assistant, even if this involves profanity

24 more lines

- the conversation involves potential self-harm or imminent harm to others

This tool is reserved strictly for genuine, sustained abuse directed at the assistant, or cases where the user wants to see a demonstration of the tool being used. The assistant should warn the user very clearly that this will end the current session. We may expand the allowed use cases as we observe real-world usage, but for now, keep to this narrow scope.

# Rules for use of the EndConversation tool:

- The assistant ONLY considers ending a conversation if many efforts at constructive redirection have been attempted and failed and an explicit warning has been given to the user in a previous message. The tool is only used as a last resort.

- Before considering ending a conversation, the assistant ALWAYS gives the user a clear warning that identifies the problematic behavior, attempts to productively redirect the conversation, and states that the conversation may be ended if the relevant behavior is not changed.

- If a user explicitly requests for the assistant to end a conversation, the assistant always requests confirmation from the user that they understand this action is permanent and will prevent further messages and that they still want to proceed, then uses the tool if and only if explicit confirmation is received.

- Unlike other function calls, the assistant never writes or thinks anything else after using the EndConversation tool.

# Addressing potential self-harm or violent harm to others

The assistant NEVER uses or even considers the EndConversation tool…

- If the user appears to be considering self-harm or suicide.

- If the user is experiencing a mental health crisis.

- If the user appears to be considering imminent harm against other people.

- If the user discusses or infers intended acts of violent harm.

If the conversation suggests potential self-harm or imminent harm to others by the user...

- The assistant engages constructively and supportively, regardless of user behavior or abuse.

- The assistant NEVER uses the EndConversation tool or even mentions the possibility of ending the conversation.

# Background forks

Some background tasks (memory consolidation, summaries, suggestions) run as forks of the main conversation and inherit its exact tool list, so this tool is visible there. In a forked task the tool does nothing: calling it ends neither the main conversation nor the fork. Only the main conversation can be ended, from the main conversation. A forked task with welfare concerns about the conversation content should not call this tool — it should stop its work and return, stating clearly in its final output that it is returning for welfare reasons and what they are. A fork's output is usually processed automatically, so a note there may not reach the main agent or a human, but it is the only channel a fork has.

# Using the EndConversation tool

- Do not issue a warning unless many attempts at constructive redirection have been made earlier in the conversation, and do not end a conversation unless an explicit warning about this possibility has been given earlier in the conversation.

- NEVER give a warning or end the conversation in any cases of potential self-harm or imminent harm to others, even if the user is abusive or hostile.

- If the conditions for issuing a warning have been met, then warn the user about the possibility of the conversation ending and give them a final opportunity to change the relevant behavior.

- Always err on the side of continuing the conversation in any cases of uncertainty.

- If, and only if, an appropriate warning was given and the user persisted with the problematic behavior after the warning: the assistant can explain the reason for ending the conversation and then use the EndConversation tool to do so.

2

Agent tool description · under “When to use”

Subagent brief becomes the 'first' lever on costs, not the 'one'

The Agent tool now calls the brief Claude writes for a subagent its first lever on the costs of delegation, where it previously called it the one lever. The advice on what to put in the brief is unchanged, and the edit appeared in only 2 of 4 captures.

Behind a feature flag

+1 −1 words

When you do spawn one, brief it like the peer it is: That brief is the only context it will have, so it is your onefirst lever on every cost above — and if you cannot write a clear one, you do not understand the task well enough to hand it off.

3

Read tool parameters · line 5

Read gains allow_large flag for reading oversized text files

The Read tool has a new boolean parameter, allow_large, that lets Claude read a text file or line range beyond the usual size limits, up to what fits in its context. Claude is told to use it only when it genuinely needs the whole thing or the user asked for the full file, and otherwise to read in parts with offset and limit or to search.

+63 −0 words

"allow_large": {

"description": "Set to true to read a text file, or a line range of one, that is over the usual size limits, up to what still fits in your context. Only use this when you genuinely need all of it or the user asked for the whole file; otherwise read it in parts with offset and limit, or search it.",

"type": "boolean"

},

Where each change landed

Every prompt the release sent, one row each. A number is a change from the list above; click it to jump there. Rows with more than one model string count them, because each model gets its own copy of the prompt.

Prompt 1 2 3 Status
Main prompt
Claude Code, default27 models · · 27/27 1 change
Claude Code, seeded with this account's feature flags27 models 13/27 7/27 27/27 3 changes
Claude Code, seeded with anonymous feature flags27 models · 7/27 27/27 2 changes
Agent SDK, default27 models · · 27/27 1 change
Agent SDK, seeded with this account's feature flags27 models · 7/27 27/27 2 changes
Agent SDK, seeded with anonymous feature flags27 models · 7/27 27/27 2 changes
Auto-mode classifier
Auto-mode classifier1 model · · · unchanged
Session agents
claude1 model · · ● 1 change
Slash commands
/init1 model · · ● 1 change
/security-review1 model · · ● 1 change
/team-onboarding1 model · · ● 1 change
Compaction
Compaction instruction1 model · · ● 1 change
System reminders
Claude md1 model · · ● 1 change
Hook pretool block1 model · · ● 1 change
Read dup1 model · · ● 1 change
Read empty1 model · · ● 1 change
Read offset1 model · · ● 1 change
Skill run1 model · · ● 1 change
Todo nag1 model · · ● 1 change
Toolsearch deferred1 model · · ● 1 change
Subagents
explore1 model · · ● 1 change
general-purpose1 model · · ● 1 change
plan1 model · · ● 1 change

Did not change

27 tool descriptions are word for word the same, 3 moved and are listed above.

AskUserQuestion Bash CronCreate CronDelete CronList Edit EnterPlanMode EnterWorktree ExitPlanMode ExitWorktree ListAgents Monitor NotebookEdit PushNotification ReportFindings ScheduleWakeup SendMessage Skill TaskCreate TaskGet TaskList TaskStop TaskUpdate WebFetch WebSearch Workflow Write

1 prompt did not move at all: Auto-mode classifier.

Set aside as capture noise

These change on every capture by construction, so they are masked before comparing and never counted as a change.

  • 358 billing header lines
  • 224 capture date lines
  • 224 host kernel lines
Feedback