You'll notice
Artifact reads, diagnostics, and database reads now check per-URL deny/ask rules before falling back to session consent.
Artifact tool permission checks gain a new rule-matching step that checks configured deny/ask rules against the specific artifact URL before falling back to session-wide consent. This covers the read_page_data, verify (diagnostics), read, and read_db actions, and permission messages now surface which rule matched, for example when Claude wants to read the structured page data of an artifact.