Sweep 19 Sep 2026 · 02:36Z Build v2.1.278 500 read Stable v2.1.267 Latest v2.1.278 Next v2.1.278 Feeds RSS JSON llms.txt Unofficial
Claude Code v2.1.267 ·

Managed-settings-only secDefault flag controls seating of the bundled sec-default plugin

A new managed-settings-only flag lets organizations put their bundled sec-default plugin ahead of user-installed plugin hooks

TierUse it nowhow much it should matter to you
Useful3my rating, 1 to 5
Signal3worth watching, 1 to 5
AreaPlugins Securitywhat it touches
KindNew Featuresin v2.1.267,
Use it now No documentation found

A new managed-settings-only flag lets organizations put their bundled sec-default plugin ahead of user-installed plugin hooks

What

A new settings field, honored only when set in managed settings (not user, project, local, or --settings), controls whether the organization's bundled "sec-default" plugin takes the outermost seat in the chain of plugin hooks, ahead of any plugins listed in prependPlugins.

Why

This keeps things like classic hooks, prompt content, managed settings, and tool policy protected from being overridden by plugins that users install themselves, since only an administrator setting managed settings can control this placement.

Read from
Names in the bundlesecDefault
How sure we are
One source agreesOne thing we can check says the same as this entry.
The name it cites is new in this buildNew in this build: secDefault

See this entry in the whole of v2.1.267 →