What
Claude Code cleans some text before Claude reads it, so that the text cannot pose as Claude Code's own messages. That cleaning now has an extra rule that neutralizes forged copies of tags Claude Code itself uses to report back to Claude, including:
function_results, which wraps the result of a tool call (an action Claude takes, such as reading a file)tool_use_error, which reports that a tool call failedsandbox_violations, which reports that a command broke the rules of the sandbox (the restricted area commands run in)persisted-output, which marks saved output
The list of wrapper tags the cleaning already recognized is now built from the same shared list of tags.
Why
This is a defence against prompt injection, where text from a tool, a web page or another writer tries to trick Claude with fake instructions. Such text can no longer pretend to be a genuine tool error or sandbox report from Claude Code.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
It is unclear exactly which kinds of text pass through this cleaning, and whether some of these tags were already caught by an older rule.