Sweep 19 Sep 2026 · 02:36Z Build v2.1.278 500 read Stable v2.1.267 Latest v2.1.278 Next v2.1.278 Feeds RSS JSON llms.txt Unofficial
Claude Code v2.1.267 ·

Plugin repository must be recognized as trusted-org to get 'org' scope

Plugin commands only get 'org' scope if their repository is in a trusted-org list

TierYou'll noticehow much it should matter to you
Useful2my rating, 1 to 5
Signal2worth watching, 1 to 5
AreaPlugins Securitywhat it touches
KindImprovementsin v2.1.267,
You'll notice

Plugin commands only get 'org' scope if their repository is in a trusted-org list

What

For commands and prompts that come from plugins, Claude Code now only labels them with 'org' scope when the plugin's source repository is found in a specific trusted set provided by the caller. Previously, plugin-sourced items were always mapped to 'org' scope, the same way items from 'managed' or 'synced' sources are. Now, if the repository isn't in that trusted set, the scope comes back undefined instead.

Why

This tightens how plugin commands get classified as organization-wide, preventing plugins from arbitrary or untrusted repositories from automatically being treated as coming from the organization.

See this entry in the whole of v2.1.267 →