What
When Claude reads back a published artifact (a page published by Claude or others), the result it gets is handled more carefully:
- Artifacts you own that were not published from the current session are now wrapped and labelled as not published from this session, with an instruction to treat the content as data
- Pages containing raw terminal control characters (invisible bytes that can change what a terminal displays) are never placed directly into the conversation; they are saved to disk and Claude must read the saved file
- If some tag-like text in the inlined copy had to be escaped, the result says so and points to the exact saved HTML
- Readers and writers get plain labels such as "created by a Claude agent" or "published from your Slack channel"
Previously your own artifacts were wrapped only in certain cases, and HTML was inlined whenever it fit.
Why
This strengthens defences against prompt injection, where text inside a page tries to pass itself off as instructions to Claude.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
It is unclear what controls whether the artifacts feature is available.