CLAUDE WATERMARK REMOVER · PRACTICAL TEST
Can cleaning JSON silently overwrite a value?
Yes. Removing a hidden character from a JSON key can turn two distinct keys into the same key. Parse a copy, inspect decoded keys, and detect collisions before changing the original.
Open the Claude text cleaner · Full measured data
Measured inputs and outputs
These are locally constructed test strings, not evidence that Claude inserts these characters. We executed the saved homepage script snapshot with a minimal DOM harness and compared exact strings. Invisible removal is enabled; the dash mode appears in each row. The observations below test this page's specific question. We make no detector-score or statistical-watermark removal claim.
| Fixture and mode | Input string and code points | Output and cleaner status | Observed before / after |
|---|---|---|---|
| Literal hidden key direct string / keep | "{\"user\":1,\"user\":2}"U+007B U+0022 U+0075 U+0073 U+0065 U+0072 U+0022 U+003A U+0031 U+002C U+0022 U+0075 U+0073 U+200B U+0065 U+0072 U+0022 U+003A U+00 … | "{\"user\":1,\"user\":2}"Removed 1 invisible character | {"keys":["user","user"],"user":1,"values":[1,2]}{"keys":["user"],"user":2,"values":[2]} |
| Escaped hidden key direct string / keep | "{\"user\":1,\"us\\u200ber\":2}"U+007B U+0022 U+0075 U+0073 U+0065 U+0072 U+0022 U+003A U+0031 U+002C U+0022 U+0075 U+0073 U+005C U+0075 U+0032 U+0030 U+0030 U+00 … | "{\"user\":1,\"us\\u200ber\":2}"No selected invisible characters found | {"keys":["user","user"],"user":1,"values":[1,2]}{"keys":["user","user"],"user":1,"values":[1,2]} |
| Hidden character in a value direct string / keep | "{\"note\":\"review\"}"U+007B U+0022 U+006E U+006F U+0074 U+0065 U+0022 U+003A U+0022 U+0072 U+0065 U+200B U+0076 U+0069 U+0065 U+0077 U+0022 U+007D | "{\"note\":\"review\"}"Removed 1 invisible character | {"keys":["note"],"user":null,"values":["review"]}{"keys":["note"],"user":null,"values":["review"]} |
Our measured collision
The literal-key fixture starts with two properties: user and us + U+200B + er. The homepage cleaner deletes that actual U+200B. Both keys then spell user. Parsing the cleaned JSON in Node.js yields one key with value 2; the earlier value 1 is lost in that parsed object. The saved output records both the complete JSON string and its parsed keys. This is a data-integrity failure even though parsing succeeds. A parser success message cannot replace a collision check.
Why the escaped fixture behaves differently
The second fixture contains six ASCII characters spelling a JSON Unicode escape. Our cleaner processes raw text and leaves that escape unchanged. JSON.parse subsequently decodes it into U+200B inside the property name, leaving two distinct properties. Therefore a zero removal count on raw JSON does not certify that decoded strings lack hidden characters. Inspect both representations deliberately; never run a replace over every escape sequence, because many escapes are legitimate content. The third fixture changes only a string value and does not merge keys.
A safe JSON workflow
Keep the source file and parse it without editing. For each object, compute proposed cleaned keys, group originals by proposed key, and stop if a group contains more than one original. Decide which field is intended using the schema or data owner. Apply approved transformations to decoded values and serialize with JSON.stringify. Recheck required fields, identifiers and types. This experiment covers these three fixtures and JavaScript parsing; another parser may reject duplicate names or retain them differently. RFC 8259 advises unique object names and describes interoperability problems when names repeat. The homepage has no JSON parser, schema checker or collision warning.
Reproduce this test
Save reproduce.cjs and tested-app.js in the same folder. Run the command below with Node.js. The harness prints its runtime, script SHA-256 and every measured row. Compare those rows with the original record. Using a newer script or runtime creates a new experiment; retain the version information with your rerun.
node reproduce.cjsReference and next check
JSON grammar and interoperability provides the relevant primary definition. The table and fixture analysis are original measurements. For broader inspection, use our Unicode inspector. Read the scope distinction before interpreting cleanup as a watermark result.