Some notes on the new Claude API web fetch tool, which I think can be used safely despite the risk of prompt injection exfiltration attacks if you're really careful with the allowed_domains parameter https://simonwillison.net/2025/Sep/10/claude-web-fetch-tool/