{"version":"2.1.235","anchor":"artifact-consent-is-pinned-to-the-exact-action-and-slug-that","canonical_anchor":"artifact-consent-is-pinned-to-the-exact-action-and-slug-that","heading":"Artifact consent is pinned to the exact action and slug that were approved","tier":"notice","area":"Artifacts","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.235\/e\/artifact-consent-is-pinned-to-the-exact-action-and-slug-that","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.235","markdown":"### Artifact consent is pinned to the exact action and slug that were approved\n\nArtifact tool approvals are now pinned to the exact action and slug approved, closing a swap-after-approval hole\n\nApproved artifact tool inputs now carry a hidden `__artifactConsentPin` property recording the approved `{action, slug}`. Execution re-reads that pin and only performs the privileged step when it matches the action and slug actually being run, throwing `asset_target_changed` if the approved target no longer matches. A sibling-tag check also rejects inputs carrying any of the other four consent tags. This closes a hole where a target could be swapped after approval for `list_assets`, `read_page_data`, `watch`, `read_db`, and `write_db`. This applies to everyone.\n\n- Area: Artifacts\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}