Anthropic Artifact Shared Publicly
Description
Claude artifacts can be shared with specific audiences. Making an artifact public exposes its contents to unauthenticated viewers on the internet. An attacker with access to sensitive artifacts can publish them publicly to push intellectual property, credentials embedded in prompts, or other confidential material outside organizational controls.
Query · esql
from logs-anthropic.audit-* metadata _id, _version, _index
| where
data_stream.dataset == "anthropic.audit" and
mv_contains(event.category, "configuration") and
event.action == "claude_artifact_sharing_updated"
| eval Esql.audience_types = FIELD_EXTRACT(anthropic.audit.audience, "type")
| where Esql.audience_types is not null and mv_contains(Esql.audience_types, "anyone_with_link")
| keep _id, _version, _index, @timestamp, event.*, organization.*, user.*, source.*, user_agent.*, anthropic.audit.*, data_stream.*, Esql.audience_types
Investigation fields
Pivot points the source recommends for triage.
@timestampevent.actionevent.idorganization.idanthropic.audit.claude_artifact_idanthropic.audit.audienceanthropic.audit.actor.typeuser.emailuser.idsource.ipuser_agent.original
Known false positives
- Users publish artifacts intentionally for demos, documentation, or external collaboration. Validate the artifact, actor, and business justification before escalating.
Analyst notes
Investigating Anthropic Artifact Shared Publicly
A Claude artifact's sharing audience includes anyone_with_link (open internet). Each sharing change is its own
alert/artifact ID.
Unauthorized = no marketing/training justification, artifact holds credentials/customer/proprietary content, or the same actor recently had chat access failures / data exports. Close as FP for intentional external demos with non-sensitive content.
Possible investigation steps
- Verify audience includes
anyone_with_linkvia flattenedaudience(FIELD_EXTRACT+mv_containsorevent.original) and noteanthropic.audit.claude_artifact_id. - Validate actor (email/IP/UA). Inspect artifact content for secrets or proprietary data when accessible.
- Look for related chat access failures or data exports from the same actor in the same window.
False positive analysis
- DevRel/training publishes are FP when the artifact is non-sensitive and a marketing/training request exists.
Response and remediation
- On unauthorized publication: revoke public sharing, inventory other artifacts modified by the same actor, and treat any embedded secrets as compromised.