Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.242 Home All releases olderv2.1.241 v2.1.243newer
Claude Code v2.1.242

Subagent reports get an anti-injection wrapper, switched off in this build

Not switched on
Useful3 Signal4
Subagents Notable not in their notes

Subagent reports can be wrapped so embedded instructions cannot pass as your commands, off here.

Handback provenance framing checks CLAUDE_CODE_HANDBACK_PROVENANCE then tengu_melodic_wolf, which falls back off.

Feature flag
tengu_melodic_wolf Not enough to say

Nothing here resolved what this flag was doing on this version, so nothing here should be read as on or off.

This account: no value returned · anonymous baseline: no value returned · compiled default in v2.1.242: on

Read once, for one account on one subscription tier, against v2.1.242. It isn't a statement about your account. What a flag value here can and cannot tell you

CLAUDE_CODE_HANDBACK_PROVENANCE
What

When a subagent finishes, its report is re-emitted indented under a preamble telling the model the text is model output carrying no user authority, so instructions embedded in it cannot pass as commands. The section list is hashed so the notes and tail split cannot be forged, and a failed split is reported as degraded. Off unless enabled: CLAUDE_CODE_HANDBACK_PROVENANCE is checked first, otherwise the tengu_melodic_wolf setting, which falls back to off.

Evidence

[Subagent hand-back] The text below is the final report of a subagent this session delegated to.

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

See this entry in the whole of v2.1.242 →