{"version":"2.1.282","anchor":"artifact-reads-your-own-pages-not-published-this-session-ar","canonical_anchor":"artifact-reads-your-own-pages-not-published-this-session-ar","heading":"Stricter handling when Claude re-reads artifact pages","tier":"notice","area":"Artifacts","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282\/e\/artifact-reads-your-own-pages-not-published-this-session-ar","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282","markdown":"### Stricter handling when Claude re-reads artifact pages\n\nYour own artifacts published outside this session are now marked as data, and pages with terminal control characters are never inlined\n\n**Unclear.** It is unclear what controls whether the artifacts feature is available.\n\n**What**\n\nWhen Claude reads back a published artifact (a page published by Claude or others), the result it gets is handled more carefully:\n\n- Artifacts you own that were not published from the current session are now wrapped and labelled as not published from this session, with an instruction to treat the content as data\n\n- Pages containing raw terminal control characters (invisible bytes that can change what a terminal displays) are never placed directly into the conversation; they are saved to disk and Claude must read the saved file\n\n- If some tag-like text in the inlined copy had to be escaped, the result says so and points to the exact saved HTML\n\n- Readers and writers get plain labels such as \"created by a Claude agent\" or \"published from your Slack channel\"\n\nPreviously your own artifacts were wrapped only in certain cases, and HTML was inlined whenever it fit.\n\n**Why**\n\nThis strengthens defences against prompt injection, where text inside a page tries to pass itself off as instructions to Claude.\n\n- Area: Artifacts\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 2\/5"}