Reading someone else's published page now asks you once, then remembers for the rest of the conversation.
What's wrong with this entry?
Reading a published page now runs through its own permission branch instead of borrowing WebFetch's. Your own artifacts are read without a prompt; the first read of someone else's asks you, and that approval is remembered for the rest of the conversation.
- A URL that is not a recognisable artifact link is rejected outright, with text telling the model to use a URL from the list or publish result.
- Deny and ask rules written for
ArtifactorWebFetchare both consulted before the read runs. - In plan mode, reading another person's artifact is refused rather than prompting, since no one can answer.
- The automatic permission classifier is never allowed to approve one of these reads on your behalf.
This is not an artifact url Claude can read. Use the artifact url from the list or publish result.
Strings lifted out of the shipped bundle, so the claim above can be checked against them.