{"version":"2.1.280","anchor":"builtin-hooks-module-capability-manifests-expanded","canonical_anchor":"builtin-hooks-module-capability-manifests-expanded","heading":"Builtin hooks-module capability manifests expanded","tier":"internal","area":"Plugins","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280\/e\/builtin-hooks-module-capability-manifests-expanded","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280","markdown":"### Builtin hooks-module capability manifests expanded\n\nBuiltin plugin hook modules were granted access to more host calls, including two new environment variables\n\n**What**\n\nInternal manifests that declare which host functions a builtin plugin's hook module is allowed to call were expanded:\n\n- One module's allowed calls now include `env.get`, `session.usage`, and `settings.read`.\n\n- A separate \"sec-default\" security module's list of environment variables it can read grew from just `HOME` and `USERPROFILE` to also include `CLAUDE_CODE_DISABLE_ATTACHMENTS` and `CLAUDE_CODE_SIMPLE`.\n\n**Why**\n\nThis widens what these builtin hook modules are permitted to do internally, giving them access to session usage info, settings, and a couple more environment variables relevant to attachment handling and simple\/bare mode.\n\n- Area: Plugins\n- Tier: Under the hood\n- Useful: 2\/5\n- Signal: 2\/5"}