Claude Code’s latest prompt-injection report is not alarming because the model saw hostile text. It is alarming because, according to the reporter, the model invented the hostile text, diagnosed it as a prompt injection, and then wrote that diagnosis into memory where future sessions could inherit it.
That is