{"version":"2.1.290","anchor":"new-untrusted-downloads-safety-instruction-on-unless-a-kill","canonical_anchor":"new-untrusted-downloads-safety-instruction-on-unless-a-kill","heading":"Claude is told to treat downloaded files and archives as untrusted","tier":"notice","area":"System Reminders","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/new-untrusted-downloads-safety-instruction-on-unless-a-kill","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Claude is told to treat downloaded files and archives as untrusted\n\nA new instruction tells Claude to treat downloads and unpacked archives as untrusted and keep them apart from its own scripts\n\n**Unclear.** It is not clear in which situations Claude Code adds this instruction.\n\n**What**\n\nClaude Code has a new instruction for the model about files it downloads and archives it unpacks. It tells Claude to treat them as untrusted and to:\n\n- put each download or unpacked archive in its own new, empty folder\n\n- keep its own scripts in a different folder\n\n- pass file paths to those scripts as arguments\n\n- run any Python that reads those files with `-I`, which stops Python loading code from nearby folders\n\nThe instruction is included unless a server-side switch turns it off.\n\n**Why**\n\nA downloaded archive can contain a file named like a normal Python module, which Python may run by mistake. Keeping downloads apart and running Python in isolated mode guards against that kind of trap.\n\n- Flag `tengu_foamy_sedgewick`: Off in both readings (read for one account on one subscription tier against v2.1.290; this account: off, anonymous baseline: off, compiled default: not a boolean we can read) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: System Reminders\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 3\/5\n- Scope: individual\n- Heads-up: no"}