A saved yes to forwarding hooks and plugins is ignored if the cloud session could have edited that file.
What's wrong with this entry?
Before honouring a previously accepted answer about forwarding your hooks and plugins to a cloud session, Claude Code now checks whether the file holding that answer sits somewhere the session can write: the checkout, a synced directory, or a sandbox write inlet. If it does, or if that cannot be determined, the stored acceptance is refused as untrusted_store and you are asked to decide again interactively.
- The refusal text is surfaced as the reason the feature is off: run
/cloud-pluginsto decide for the session. - Only reachable when device-hook or cloud-plugin forwarding is in play (
claude --cloud); the distrust check itself always runs there.
the saved answer here could be changed by this session; run /cloud-plugins to decide for it
Strings lifted out of the shipped bundle, so the claim above can be checked against them.