{"version":"2.1.235","anchor":"cloudframe-sdk-messages-are-validated-instead-of-trusted","canonical_anchor":"cloudframe-sdk-messages-are-validated-instead-of-trusted","heading":"Cloud\/frame SDK messages are validated instead of trusted","tier":"internal","area":"Sessions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.235\/e\/cloudframe-sdk-messages-are-validated-instead-of-trusted","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.235","markdown":"### Cloud\/frame SDK messages are validated instead of trusted\n\nCloud\/frame SDK messages are now validated field-by-field instead of trusted\n\nThe adapter that converts remote frame messages into local ones now validates each field before using it. A missing or non-string `uuid` is replaced with a freshly generated one and logged at error level. Frames whose `content` is not a string are dropped, as are `tool_progress` frames with non-string names or non-finite elapsed time, and `compact_boundary` frames without metadata.\n\nFor init frames, `model`, `cwd`, `slash_commands`, `mcp_servers` and `tools` are each checked individually: if any arrives in the wrong shape, it is ignored and logged rather than adopted.\n\n- Area: Sessions\n- Tier: Under the hood\n- Useful: 1\/5\n- Signal: 1\/5"}