Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.227 Home All releases olderv2.1.226 v2.1.228newer
Claude Code v2.1.227

Subagent hand-back text is checked by the safeguard review

You'll notice
Useful4 Signal4
Subagents

A subagent's final text is now treated as untrusted and screened for prompt injection.

What

When a subagent finishes, the final text it hands back to the parent agent is now itself reviewed by the auto-mode safeguard, treated as untrusted agent-authored output that could relay a prompt injection. Previously only the subagent's tool calls were reviewed.

Details
  • The hand-back text is wrapped in <subagent_hand_back> tags and submitted as the action to evaluate.
  • The review now also runs when the subagent made no reviewable tool calls but did produce hand-back text.
  • The allowed, blocked, refused and unavailable outcomes were reworked so a policy refusal is no longer reported as unavailable.
Evidence

<subagent_hand_back>

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.227 →