You'll notice
Artifact reads now respect your deny rules matched on the artifact URL.
Artifact read and asset requests, specifically list_assets and read_asset (but not delete_asset), are now checked against the user's permission deny rules matched on the artifact URL before proceeding. A request blocked this way is refused with a message naming the specific tool and deny rule, for example "Reading this artifact is blocked by your ${toolName} deny rule."