From the Inside Claude Code: The Claude Code Ecosystem architecture map

Every defence against hidden instructions rests on one small sanitizer

risk · high · verified

sanitizer.ts is imported by 8 files across 7 modules: the prompt builder, the context formatter, the tracking comment, the comment and inline comment MCP servers, post-run reporting and the run orchestrator. It is a list of regexes with no other layer behind it, so a regression silently reopens every inbound and outbound path at once.

Impact: A missed pattern, such as a new Unicode tag block or an HTML construct, lets hidden instructions reach Claude everywhere at once.

Recommendation (small effort): Add a shared fixture test of known hiding tricks that runs against sanitizeContent and against each caller's output, so a gap fails CI at every entry point.

The trail

  1. Content Sanitizer
  2. Prompt Builder
  3. Context Formatter
  4. GitHub Comment Server
Open on the map

More from this board

© 2026 Syntaxia App Platform Ltd.

Syntaxia App Platform Ltd. Registered in England and Wales, company no. 15272701 Registered office: 3rd Floor, 86–90 Paul Street, London EC2A 4NE, United Kingdom contact@provenmap.com