Approved artifact tool inputs now carry a hidden __artifactConsentPin property recording the approved {action, slug}. Execution re-reads that pin and only performs the privileged step when it matches the action and slug actually being run, throwing asset_target_changed if the approved target no longer matches. A sibling-tag check also rejects inputs carrying any of the other four consent tags. This closes a hole where a target could be swapped after approval for list_assets, read_page_data, watch, read_db, and write_db. This applies to everyone.
Artifact consent is pinned to the exact action and slug that were approved
Artifact tool approvals are now pinned to the exact action and slug approved, closing a swap-after-approval hole
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
ArtifactsArea: what it touches
Bug FixesKind: in v2.1.235,
Bug FixesSection of the release