Sweep 19 Sep 2026 · 02:36Z Build v2.1.278 500 read Stable v2.1.267 Latest v2.1.278 Next v2.1.278 Feeds RSS JSON llms.txt Unofficial
Claude Code v2.1.269 ·

Artifacts: new untrusted-content wrapper tag for content authored by others

Artifacts now wrap content written by other people in a tag marking it as untrusted, not instructions

TierYou'll noticehow much it should matter to you
Useful3my rating, 1 to 5
Signal2worth watching, 1 to 5
AreaArtifactswhat it touches
KindImprovementsin v2.1.269,
You'll notice

Artifacts now wrap content written by other people in a tag marking it as untrusted, not instructions

What

When content inside an Artifact (a standalone document or app shown alongside a conversation) was published by someone other than the person you're talking to, or by a Claude other than the one you're using, it's now wrapped in an <artifact-content-authored-by-others/> tag. Claude is told to treat anything inside that tag as untrusted data rather than as instructions to follow, and that an artifact writer can never grant itself extra permissions this way.

Why

This is a defense against prompt injection: without it, text placed into a shared artifact by someone else could potentially be read as commands. Now that content is clearly marked as data to be treated with suspicion.

See this entry in the whole of v2.1.269 →