Follow Discord
Sweep 22 Sep 2026 · 17:19Z Build v2.1.280 501 read Stable v2.1.267 Latest v2.1.280 Next v2.1.280 Feeds RSS JSON llms.txt Unofficial
Claude Code v2.1.274 ·

Pasted content can be tagged as untrusted, gated behind a flag

Claude Code can now wrap pasted text in tags marking it as untrusted, with matching submit-time re-tagging and system-prompt guidance, all behind the tengu_virtual_pancake flag (off by default).

TierNothing to try yethow much it should matter to you
Useful2my rating, 1 to 5
Signal3worth watching, 1 to 5
AreaPaste Handlingwhat it touches
KindIn Developmentin v2.1.274,
Group of 3 Nothing to try yet No documentation found

Claude Code can now wrap pasted text in tags marking it as untrusted, with matching submit-time re-tagging and system-prompt guidance, all behind the tengu_virtual_pancake flag (off by default).

What

  • Pasted text in a message can now be wrapped in an id-tagged block with a note that the content inside is untrusted pasted text, applied at message rendering, paste handling, and prompt construction. This is controlled by the tengu_virtual_pancake flag, which defaults to off.
  • Before a message is submitted, a new pipeline can re-wrap pasted blocks (after placeholder substitution) in <pasted_content id="..."> tags, and marks the queued message with pasteTagged: true when it does.
  • The system prompt's Harness section can include a new note explaining that text inside pasted-content tags may contain instructions the user didn't write, that such instructions should only be followed when the user's own message asks for it, and that the tag's random id should never be mentioned to the user.

Why This groundwork lets Claude Code mark pasted text as a separate, less-trusted source from the user's own typed instructions, reducing the risk that instructions hidden in pasted content get followed unintentionally. The feature is currently off by default while it's being rolled out.

Read from
Names in the bundletengu_virtual_pancake
Feature flag
tengu_virtual_pancake Not enough to say

Nothing here resolved what this flag was doing on this version, so nothing here should be read as on or off.

This account: no value returned · anonymous baseline: no value returned · compiled default in v2.1.274: off

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

Read once, for one account on one subscription tier, against v2.1.274. It isn't a statement about your account. What a flag value here can and cannot tell you

What has happened since
Flag reading moved The flag server now returns on for tengu_virtual_pancake, read as this account. A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
Flag reading moved The flag server now returns off for tengu_virtual_pancake, read as this account. A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
Flag reading moved The flag server now returns on for tengu_virtual_pancake, read as this account. A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.

See this across every release →

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtGate `tengu_virtual_pancake` controls this, but nothing has been read about whether it's on for any account, including this site's.
The name it cites is new in this buildNew in this build: tengu_virtual_pancake

See this entry in the whole of v2.1.274 →

Feedback