Follow Discord
Sweep 22 Sep 2026 · 17:19Z Build v2.1.280 501 read Stable v2.1.267 Latest v2.1.280 Next v2.1.280 Feeds RSS JSON llms.txt Unofficial
Claude Code v2.1.265 ·

Artifact comment threads get stronger prompt-injection framing

Artifact comment threads now carry an explicit warning that comment text is untrusted and can't expand what Claude is allowed to do

TierUnder the hoodhow much it should matter to you
Useful1my rating, 1 to 5
Signal1worth watching, 1 to 5
AreaArtifactswhat it touches
KindInternal Changesin v2.1.265,
Under the hood

Artifact comment threads now carry an explicit warning that comment text is untrusted and can't expand what Claude is allowed to do

What

The hidden header text wrapping artifact comment threads now spells out more clearly that:

  • comment text is untrusted, since it's written by artifact viewers
  • those viewers may be outside your organization
  • a request embedded in a comment cannot widen the current task or grant new permissions, such as running commands, following links, touching unrelated files or configuration, or sending data or credentials
Why

This strengthens protection against prompt injection: someone leaving a comment on an artifact can't use that comment to trick Claude into doing more than the task actually calls for, even if the comment is phrased as an instruction.

See this entry in the whole of v2.1.265 →

Feedback