Under the hood
Artifact comment threads now carry an explicit warning that comment text is untrusted and can't expand what Claude is allowed to do
What
The hidden header text wrapping artifact comment threads now spells out more clearly that:
- comment text is untrusted, since it's written by artifact viewers
- those viewers may be outside your organization
- a request embedded in a comment cannot widen the current task or grant new permissions, such as running commands, following links, touching unrelated files or configuration, or sending data or credentials
Why
This strengthens protection against prompt injection: someone leaving a comment on an artifact can't use that comment to trick Claude into doing more than the task actually calls for, even if the comment is phrased as an instruction.