{"version":"2.1.280","anchor":"sanitization-of-a-spoofable-from-plugin-attribute-in-tagged","canonical_anchor":"sanitization-of-a-spoofable-from-plugin-attribute-in-tagged","heading":"Sanitization of a spoofable from-plugin attribute in tagged content","tier":"internal","area":"Permissions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280\/e\/sanitization-of-a-spoofable-from-plugin-attribute-in-tagged","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280","markdown":"### Sanitization of a spoofable from-plugin attribute in tagged content\n\nClaude Code now strips fake from-plugin attributes from text before checking internal task tags\n\n**What**\n\nClaude Code uses internal tags to track metadata about tasks and subagents (helper AI instances it delegates work to), including attributes like `from`, `from-session`, `hop-chain`, `from-name`, `from-mode`, and `from-plugin`. A new step now strips out any `from-plugin=\"...\"` attribute found in ordinary text before that text is checked against the internal tag format.\n\n**Why**\n\nWithout this, content coming from a user or from a tool's output could include a fake `from-plugin` attribute crafted to look like it came from Claude Code's own internal tagging system. Stripping it first closes off that spoofing path, so internal tag matching can't be fooled by attacker-supplied text claiming to originate from a plugin.\n\n- Area: Permissions\n- Tier: Under the hood\n- Useful: 1\/5\n- Signal: 1\/5"}