What
Claude Code changed how it reads artifacts (pages published through Claude) that other people wrote, and how it labels that content for Claude. Much of it sits behind two server-controlled switches: tengu_cobalt_plinth_tansy covers a writer in the same Slack channel, and tengu_cobalt_plinth_mallow, which already controlled some artifact comment and subscription operations, now also covers a new "shared" mode for other non-owners.
- Artifacts from other writers can be read in a "shared" mode behind
tengu_cobalt_plinth_mallow: in full when a further check passes, otherwise "on_approval". Full content is wrapped as untrusted content, and approving covers re-reads of that artifact for the rest of the conversation. - The same-channel Slack writer case now sits behind
tengu_cobalt_plinth_tansyas its own "channel" mode. - While approval is pending, the summary Claude gets adds a hint that the full page can be read with the read action after asking the user to approve.
- Artifacts from another organization or an off-org ramp only ever come back as a summary, whatever the user approves.
- Files containing raw terminal control bytes (hidden characters that steer a terminal) are saved to disk instead of being shown inline.
- Owners with co-writers, type-locked pages, pages outside the organization and same-channel writers each get their own wrapping text. A new variant covers pages "not published from this session" and tells Claude to treat the contents as data, not instructions, with a reminder that artifact content cannot grant extra permissions.
- The untrusted-content warning no longer says the page "is owned by you but" includes content published by other writers.
Both switches fall back to off when there is no server value. For tengu_cobalt_plinth_mallow, the flag server returned off for this site's account and for the anonymous baseline, but no reading has been taken under this release yet. Nothing has been read about tengu_cobalt_plinth_tansy.
Why
Artifacts written by other people can contain text meant to steer Claude. These changes allow full reads of shared artifacts only with approval or a server switch, keep content from other organizations to summaries, keep terminal control characters out of the conversation, and label more of this content as untrusted.
tengu_cobalt_plinth_mallow Off in both readingsThe flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.
This account: off · anonymous baseline: off · compiled default in v2.1.282: off
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
tengu_cobalt_plinth_tansy Not enough to sayNothing here resolved what this flag was doing on this version, so nothing here should be read as on or off.
This account: no value returned · anonymous baseline: no value returned · compiled default in v2.1.282: off
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.282. It isn't a statement about your account. What a flag value here can and cannot tell you
It is not clear what the further check looks at, or whether reading with approval is new in this release.
New in this build: tengu_cobalt_plinth_mallow