Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.222 Home All releases olderv2.1.221 v2.1.223newer

Tool-input string extraction hardened against hostile objects

Under the hood
Useful2 Signal0
Permissions

Reading tool inputs is now hardened so a crafted object cannot run code during extraction.

What

The helper that pulls values like command, file_path, prompt and args out of tool input no longer trusts the shape of the object it is given.

Details
  • Rejects Proxy objects outright.
  • Reads own property descriptors rather than invoking getters, so extraction cannot run attacker code.
  • Bails on array-like values whose length is not a safe integer or exceeds the cap.
Evidence

OYa.types.isProxy(e)

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

See this entry in the whole of v2.1.222 →