Unclear It is not clear in which situations Claude Code adds this instruction.
Claude Code has a new instruction for the model about files it downloads and archives it unpacks. It tells Claude to treat them as untrusted and to:
- put each download or unpacked archive in its own new, empty folder
- keep its own scripts in a different folder
- pass file paths to those scripts as arguments
- run any Python that reads those files with
-I, which stops Python loading code from nearby folders
The instruction is included unless a server-side switch turns it off.
A downloaded archive can contain a file named like a normal Python module, which Python may run by mistake. Keeping downloads apart and running Python in isolated mode guards against that kind of trap.
tengu_foamy_sedgewick Off in both readingsThe flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.
This account: off · anonymous baseline: off · compiled default in v2.1.290: not a boolean we can read
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.290. It isn't a statement about your account. What a flag value here can and cannot tell you
It is not clear in which situations Claude Code adds this instruction.