What it is
A new sec-default hooks module blocks plugins from bypassing policy settings and MCP server allowlists on managed and Team/Enterprise accounts
Not Anthropic's. This is the line from the earliest changelog entry here that named it, v2.1.267.
Presence across releases
2Build by build
12One row per release since the first build this name was read out of. Absent means the build was read and the name was not in it, never mined means no bundle for that release was ever archived, and a declared type or a default is only ever what that release's own bundle stated.
First cited
3The earliest release whose published evidence quoted secDefault was v2.1.267, 9 Sep 2026. That is the oldest release this project wrote about it, so it is a floor on the name's age and not the release that introduced it. It is not a presence reading: which builds carried the name is the table above.
Read out of the published npm bundle release by release, and out of Anthropic's own documentation as this site captured it. Nothing on this page is a description anybody here wrote about what the settings key does. All settings keys.