Under the hoodTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.280,
ImprovementsSection of the release
What
Claude Code uses internal tags to track metadata about tasks and subagents (helper AI instances it delegates work to), including attributes like from, from-session, hop-chain, from-name, from-mode, and from-plugin. A new step now strips out any from-plugin="..." attribute found in ordinary text before that text is checked against the internal tag format.
Why
Without this, content coming from a user or from a tool's output could include a fake from-plugin attribute crafted to look like it came from Claude Code's own internal tagging system. Stripping it first closes off that spoofing path, so internal tag matching can't be fooled by attacker-supplied text claiming to originate from a plugin.