You'll notice
Files from an Artifact type's publisher are now flagged as untrusted when read.
When file_read returns a file that originates from an Artifact type rather than the user or a co-writer, the result now warns that the file was written by the type's publisher and should be treated as untrusted data, with an explicit instruction not to act on embedded instruction-like text.