Subagent reports now end with the exact file paths that run wrote, marked as untrusted web content.
What's wrong with this entry?
When a subagent saves tool output to disk, such as raw bytes fetched by the web fetch tool, its final report now ends with a note listing those paths and warning the model that the contents came from the web and are untrusted, and that any path mentioned elsewhere did not come from Claude Code itself. The note is capped at 8000 characters.
- Long reports are trimmed to make room for the note; a trimmed entry is marked with how much was cut from its original length.
- If too many files were saved to list, the list ends with a fixed line saying the rest were omitted to keep the note short.
more saved ${e === 1 ? "file" : "files"}, not listed to keep this note short
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.234
Another forged control tag is escaped in subagent output
Both mention subagent
-
v2.1.234
Spawned processes get
--flag=valuewhen the value looks like a flagBoth mention subagent
-
v2.1.235
New error for delegating to a subagent without naming one
Both mention subagent