{"version":"2.1.282","anchor":"new-sanitizer-rule-neutralizes-harness-signal-tags-in-untrus","canonical_anchor":"new-sanitizer-rule-neutralizes-harness-signal-tags-in-untrus","heading":"Forged tool-result and sandbox tags in untrusted text are now neutralized","tier":"notice","area":"Elsewhere","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282\/e\/new-sanitizer-rule-neutralizes-harness-signal-tags-in-untrus","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282","markdown":"### Forged tool-result and sandbox tags in untrusted text are now neutralized\n\nText that imitates Claude Code's own tool-result, tool-error or sandbox tags is now neutralized before Claude reads it\n\n**Unclear.** It is unclear exactly which kinds of text pass through this cleaning, and whether some of these tags were already caught by an older rule.\n\n**What**\n\nClaude Code cleans some text before Claude reads it, so that the text cannot pose as Claude Code's own messages. That cleaning now has an extra rule that neutralizes forged copies of tags Claude Code itself uses to report back to Claude, including:\n\n- `function_results`, which wraps the result of a tool call (an action Claude takes, such as reading a file)\n\n- `tool_use_error`, which reports that a tool call failed\n\n- `sandbox_violations`, which reports that a command broke the rules of the sandbox (the restricted area commands run in)\n\n- `persisted-output`, which marks saved output\n\nThe list of wrapper tags the cleaning already recognized is now built from the same shared list of tags.\n\n**Why**\n\nThis is a defence against prompt injection, where text from a tool, a web page or another writer tries to trick Claude with fake instructions. Such text can no longer pretend to be a genuine tool error or sandbox report from Claude Code.\n\n- Area: Elsewhere\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}