{"version":"2.1.284","anchor":"peer-and-coordinator-messages-can-be-wrapped-in-id-tagged-sy","canonical_anchor":"new-claude-code-whimsical-elephant-env-var-overrides-the-ten","heading":"Relayed agent messages can be wrapped in id-tagged system reminders, with escaping so text cannot fake one (tengu_whimsical_elephant)","tier":"notice","area":"Agents","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/peer-and-coordinator-messages-can-be-wrapped-in-id-tagged-sy","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Relayed agent messages can be wrapped in id-tagged system reminders, with escaping so text cannot fake one (tengu_whimsical_elephant)\n\nPeer, coordinator and forwarded messages can be wrapped in id-tagged system reminders, and text that imitates a reminder tag is now escaped\n\n**Unclear.** It is not clear whether the wrapping itself is new in this release or only the switch that controls it.\n\n**What**\n\nA system reminder is a block of text Claude Code adds to the conversation, marked with `<system-reminder>` tags, that Claude treats as coming from Claude Code rather than from a person. This release adds reminders that carry a random id, and escaping so other text cannot pass itself off as one.\n\n- A new gate, `tengu_whimsical_elephant`, controls the feature, and the new environment variable `CLAUDE_CODE_WHIMSICAL_ELEPHANT` is checked first and overrides it. The fallback is false. The variable was also added to an internal list of environment variables.\n\n- When the feature is on, queued messages from a forwarded turn, a peer (another Claude session, unless it is an activity observation) or a coordinator get a random `reminderId`.\n\n- Those messages are then wrapped in `<system-reminder id=\"...\">` ... `<\/system-reminder id=\"...\">`, where the id is 16 to 32 hex characters, instead of being passed through unwrapped.\n\n- Inside the wrapper, any `<\/system-reminder` in the content becomes `&lt;\/system-reminder`, so the content cannot close the reminder early.\n\n- User or queued-command text that begins with `<system-reminder` followed by a space has its leading `<` rewritten as `&lt;`. Text sent with a valid reminder id is exempt, and a queued command's text is merged into the previous user message when it matches that command's reminder id.\n\n**Why**\n\nThis changes how messages passed between agents are framed to Claude, and it closes a way for tool output, typed text or relayed messages to pose as a message from Claude Code itself.\n\n- Area: Agents\n- Tier: You'll notice\n- Useful: 5\/5\n- Signal: 5\/5\n- Present in the build but not switched on"}