You'll notice
Content read from another organization's artifact is now explicitly flagged as untrusted
What
Claude Code now tracks, per tool use, whether the user has consented to reading artifacts belonging to another organization. When content from such an artifact (either shared directly from another organization, or a public artifact from outside the user's organization) is included, it's now given an explicit warning label instructing that it be treated as untrusted input.
Why
This reduces the risk of content from outside an organization being treated as trustworthy instructions or data by default, similar to how other external content is already handled.