Prompt and agent hooks now share a rule on reading "ok" and ignoring injected instructions#
Hook evaluator prompts now say "ok" true allows and false blocks, accept rule-style checks, and ignore instructions hidden in event data
Hooks that ask a model to judge an action now treat its answer as a plain allow or block. An "ok" value of true lets the action go ahead, and false stops it. Prompt hooks now ask whether an action may go ahead, not whether a condition is met. Agent hooks must now always give a reason for their verdict. Both kinds are told to ignore instructions hidden in the content they check. The instructions Claude gets for the Monitor tool were also rewritten, and now say its script runs in the same shell environment as Bash.
New text was added to the instructions Claude gets for the SendMessage tool. It only appears under some account settings, so it is not switched on for most people yet. The added text includes an example of a message sent to a worker.
Written by our agent from the shipped bundle, not by Anthropic.
Want the reasoning? Read walks every section of this release, each entry opening to what changed and why.
Read this release → Every row →Smaller changes and internals, grouped as the pipeline found them. Nothing is dropped, it is only further down.
Hook evaluator prompts now say "ok" true allows and false blocks, accept rule-style checks, and ignore instructions hidden in event data
Agent-type hooks are now told to always give a reason with their verdict and to ignore instructions hidden in the content they check
The agent-hook checker is now told "ok" true allows the action and false blocks it, and to ignore instructions inside what it checks
The instructions Claude gets for the Monitor tool were rewritten, and now say the script runs in the same shell environment as Bash
Text was added to the SendMessage tool instructions Claude receives under some account settings, including an example message to a worker
Published verbatim by Anthropic for v2.1.294. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.
Of these 2 bullets, 0 name something an entry on this page also names, 2 name something no entry here does, and 0 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.
prompt and agent hooks written as instructions (such as "Block commands that...") allowing what they should block
No entry names this prompt hooks on Stop and SubagentStop written as instructions (such as "Carry on if the build is broken") are judged, so Claude is less likely to stop early
No entry names this No change to the system prompt since v2.1.293.
Claude Code, interactive mode
747 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.
What's wrong with this entry?