{"version":"2.1.284","anchor":"memory-file-write-lint-refuse-or-strip-invisible-characters","canonical_anchor":"memory-file-write-lint-refuse-or-strip-invisible-characters","heading":"Memory-file writes can be checked for hidden characters and fake system tags","tier":"soon","area":"Memory","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/memory-file-write-lint-refuse-or-strip-invisible-characters","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Memory-file writes can be checked for hidden characters and fake system tags\n\nA new check can refuse or clean memory files containing invisible characters or tag-like text; it falls back to off unless enabled remotely\n\n**What**\n\nClaude Code keeps persistent memory as markdown (`.md`) files in a memory folder. A new check can now run when Claude's Write or Edit tools (the tools it uses to create and change files) touch one of those files:\n\n- A memory file whose name or path contains invisible or control characters is always refused.\n\n- In your main conversation, content with invisible characters or text shaped like an internal tag, such as `<system-reminder>`, is refused with a message explaining why.\n\n- In background work and subagents (helper agents Claude starts on its own), those characters and tags are removed instead of the write being refused.\n\n- An edit that has nothing left to change after that clean-up is refused.\n\nThe check sits behind the `tengu_memdir_write_lint` gate, which falls back to off unless it is switched on remotely.\n\n**Why**\n\nMemory files are read back into later sessions, so hidden characters or fake tags in them could be used to slip instructions to Claude. Where the check is enabled, some memory writes that used to succeed will fail with these new messages.\n\n- Flag `tengu_memdir_write_lint`: Not enough to say (read for one account on one subscription tier against v2.1.284; this account: no value returned, anonymous baseline: no value returned, compiled default: off) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: Memory\n- Tier: Nothing to try yet\n- Useful: 3\/5\n- Signal: 4\/5\n- Present in the build but not switched on"}