{"version":"2.1.281","anchor":"tag-spoofing-scrub-now-matches-unicode-look-alike-and-case-f","canonical_anchor":"tag-spoofing-scrub-now-matches-unicode-look-alike-and-case-f","heading":"Tag-spoofing scrub now matches Unicode look-alike and case-folded spellings","tier":null,"area":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/tag-spoofing-scrub-now-matches-unicode-look-alike-and-case-f","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Tag-spoofing scrub now matches Unicode look-alike and case-folded spellings\n\nFake protected tags written with look-alike Unicode letters or odd capitals are now caught and neutralised\n\n**What**\n\nClaude Code scrubs text that tries to pass itself off as one of its own protected tags, such as a fake `<channel ...` opener. The scrub, `createTagFormScrub`, now converts non-ASCII characters and mixed capitals to plain lowercase ASCII before comparing names. This means look-alike letters from other alphabets and unusual capitalisation are caught too. A matching fake tag has its opening changed to `<\\`, so it no longer reads as a tag.\n\n**Why**\n\nText from files, web pages or tools is harder to disguise as a genuine Claude Code message. Swapping in a similar-looking character no longer gets a fake tag past the check."}