Vibe Coding
Claude Code's Artifact tool now treats an artifact written by someone else as untrusted and flags embedded instructions instead of relaying them
2.1.265 changes how the Artifact tool summarises a page authored by another party: the content is handled as untrusted input, and instructions embedded in it are reported rather than passed through into the conversation. The same release refuses an artifact publish when none of the connector tool names it declares actually exist, and warns when only some are missing. Both are harness-level injection defenses in the same shape as the CapScope paper's argument.
↳ Follow the thread