Saving artifact files outside the scratchpad now needs a human, not the automatic approver.
What's wrong with this entry?
When Claude saves a file it fetched from an artifact to a path outside the session scratchpad, or inside it under a name the file-edit safety rules watch (git, hook, tool or agent configuration), the approval can no longer be granted by the automatic permission classifier. A human has to approve it.
- The stated reason is that both the path and the contents were chosen by whoever wrote the artifact, not by you.
- Ordinary saves to unremarkable names inside the scratchpad are unaffected.
writes a file outside the session scratchpad, where the project's tools may act on it, with a path and contents chosen by a writer of the artifact \u2014 approval must come from the user, not the auto-permission classifier
Strings lifted out of the shipped bundle, so the claim above can be checked against them.