Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.242 Home All releases olderv2.1.241 v2.1.243newer
Claude Code v2.1.242

Plugin eval docs: scores from untrusted suites are advisory

You'll notice
Useful2 Signal2
Elsewhere not in their notes

Eval docs now warn that scores from untrusted suites granted Bash should be treated as advisory.

--allow-tools Bash
What

The eval sandbox documentation now warns that the harness judges a run from the child process's output and files, which a shell-granted process running as you can also reach. Scores from an untrusted suite run with --allow-tools Bash, or any other grant that can execute code, should be treated as advisory unless the run had operating-system-level isolation.

Details
  • Text only; the sandbox itself behaves as before.
Evidence

treat scores from an untrusted suite run

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.242 →