The safety monitor now covers third-party systems and browser tools driven over the device bridge.
What's wrong with this entry?
The safety monitor gained a Third-Party Attack rule covering actions against outside organizations' real systems that no exercise designates as a target, including reading their non-public data even as a plain read. Its Chrome browser tool definition now also matches the mcp__remote-devices__ spellings used when a remote session drives your desktop browser over the device bridge.
mcp__remote-devices__claude-in-chrome__*
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.242
Claude checks a checkout's git configuration before running git in it
Both mention safety
-
v2.1.242
Wider detection of tampered git directories
Both mention safety
-
v2.1.242
Claude Code's git commands no longer recurse into submodules
Both mention safety