Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.282 ·

Forged tool-result and sandbox tags in untrusted text are now neutralized

Text that imitates Claude Code's own tool-result, tool-error or sandbox tags is now neutralized before Claude reads it

You'll notice Improvements
JSON All of v2.1.282
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
ElsewhereArea: what it touches
ImprovementsKind: in v2.1.282,
ImprovementsSection of the release
What

Claude Code cleans some text before Claude reads it, so that the text cannot pose as Claude Code's own messages. That cleaning now has an extra rule that neutralizes forged copies of tags Claude Code itself uses to report back to Claude, including:

  • function_results, which wraps the result of a tool call (an action Claude takes, such as reading a file)
  • tool_use_error, which reports that a tool call failed
  • sandbox_violations, which reports that a command broke the rules of the sandbox (the restricted area commands run in)
  • persisted-output, which marks saved output

The list of wrapper tags the cleaning already recognized is now built from the same shared list of tags.

Why

This is a defence against prompt injection, where text from a tool, a web page or another writer tries to trick Claude with fake instructions. Such text can no longer pretend to be a genuine tool error or sandbox report from Claude Code.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is unclear exactly which kinds of text pass through this cleaning, and whether some of these tags were already caught by an older rule.

See this entry in the whole of v2.1.282 →

Feedback