Publishing artifact files now forces a person-only confirmation when a copied file's read permission was judged deceptive or unexaminable
When Claude Code publishes or copies files as part of an artifact, it now checks the read-permission decision made for each file. If any file was flagged as "deceptive" or "unexaminable", and the request is happening in plan mode, through a served call, or with redirected roots, the confirmation for that publish is forced to require approval from an actual person rather than something a hook or another agent could silently approve on the user's behalf.
This closes a gap where a suspicious or unreadable file could be published as part of an artifact without a human actually looking at it, ensuring risky publishes always get a genuine human check.