Marketplaces can declare command plugin sources, and admins can block them with one setting.
What's wrong with this entry?
A marketplace can now declare a command plugin source, where Claude Code runs that command on your machine to produce the plugin directory. Installs and updates prompt before running the command. A new managed setting disableCommandPluginSources turns it off; when it is unset, the existing allowManagedHooksOnly managed setting decides, and an invalid value for either key is treated as disabled.
commandis now listed alongside github, git-subdir, npm, url and archive in marketplace validation messages.- Each installation records the command that produced it, the directory it produced, and the directories previous runs produced, so the sandbox keeps refusing writes to superseded producer directories.
- Both settings keys are read from managed settings only, so a user or project settings file cannot re-enable this.
disableCommandPluginSources
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.238
Managed settings can refuse plugin sources and marketplace updates
Both mention disable command source allow managed hook only
-
v2.1.238
Plugin marketplaces and archives can mint HTTP headers from a command
Both mention disable command source allow managed hook only
-
v2.1.242
Administrators and --bare can block plugin hooks from loading
Both mention disable allow managed hook only