Claude Code keeps persistent memory as markdown (.md) files in a memory folder. A new check can now run when Claude's Write or Edit tools (the tools it uses to create and change files) touch one of those files:
- A memory file whose name or path contains invisible or control characters is always refused.
- In your main conversation, content with invisible characters or text shaped like an internal tag, such as
<system-reminder>, is refused with a message explaining why. - In background work and subagents (helper agents Claude starts on its own), those characters and tags are removed instead of the write being refused.
- An edit that has nothing left to change after that clean-up is refused.
The check sits behind the tengu_memdir_write_lint gate, which falls back to off unless it is switched on remotely.
Memory files are read back into later sessions, so hidden characters or fake tags in them could be used to slip instructions to Claude. Where the check is enabled, some memory writes that used to succeed will fail with these new messages.
tengu_memdir_write_lint Not enough to sayNothing here resolved what this flag was doing on this version, so nothing here should be read as on or off.
This account: no value returned · anonymous baseline: no value returned · compiled default in v2.1.284: off
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.284. It isn't a statement about your account. What a flag value here can and cannot tell you
New in this build: tengu_memdir_write_lint