{"version":"2.1.287","anchor":"new-escaped-assignment-secret-redaction-rule","canonical_anchor":"new-escaped-assignment-secret-redaction-rule","heading":"Secrets inside escaped quoted text are now hidden","tier":"notice","area":"Secret Redaction","scope":null,"heads_up":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.287\/e\/new-escaped-assignment-secret-redaction-rule","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.287","markdown":"### Secrets inside escaped quoted text are now hidden\n\nClaude Code's secret-hiding rules can now catch a secret assigned inside text with backslash-escaped quotes, such as JSON nested in a string\n\n**Unclear.** It is not clear where this secret-hiding list is applied, for example usage data, transcripts or both.\n\n**What**\n\nClaude Code keeps a list of patterns it uses to spot secrets, such as passwords and keys, and hide them. The list has a new rule, `sensitive-assign-escaped`. It catches secrets assigned inside text whose quote marks are escaped with a backslash, like `\\\"`. This happens with JSON stored inside another string.\n\nThe rule only hides the matching text and does not do anything else with it. It is marked as low confidence.\n\n**Why**\n\nSecrets inside escaped JSON used to get past the secret-hiding list. Now they get hidden.\n\n- Area: Secret Redaction\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}