DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.
Deny rules can now be labelled as third-party attack risk alongside existing categories.
What's wrong with this entry?
Anonymous. No account, no email.
What
A third_party_attack identifier joins the risk categories used when rendering deny rules from settings, sitting between the shared-scratch and TLS-weakening entries.
Evidence
third_party_attack
Strings lifted out of the shipped bundle, so the claim above can be checked against them.