{"version":"2.1.282","anchor":"allowmanagedpermissionrulesonly-now-also-ignores-allowed","canonical_anchor":"allowmanagedpermissionrulesonly-now-also-ignores-allowed","heading":"allowManagedPermissionRulesOnly now also withholds allowed-tools from user and project skills","tier":"notice","area":"Permissions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282\/e\/allowmanagedpermissionrulesonly-now-also-ignores-allowed","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282","markdown":"### allowManagedPermissionRulesOnly now also withholds allowed-tools from user and project skills\n\nUnder allowManagedPermissionRulesOnly, allowed-tools in untrusted skill, command and plugin frontmatter no longer grants tool permissions\n\n**Unclear.** Only the setting's description is known to have changed, so it is not settled whether the enforcement itself is new in this release.\n\n**What**\n\nWhen the managed policy setting `allowManagedPermissionRulesOnly` is on, the `allowed-tools` list in skill and command frontmatter (the header at the top of a skill file) no longer grants tool permissions unless it comes from a trusted source. Until now the setting covered permission rules from settings files and `--allowedTools`.\n\n- Ignored: `allowed-tools` from skills and custom commands in user, project and `--add-dir` sources, and from plugins adopted from a `.claude-plugin` manifest inside those skills directories.\n\n- Kept, per the setting's description: other plugins, managed skills and bundled skills. Plugins from the official skills marketplace are exempt.\n\n- Skills and plugin commands now look up their `allowed-tools` each time they run. When a grant is dropped, a warning is logged, and in text print mode a line on standard error tells you to ask an admin.\n\n- A plugin command whose frontmatter declares `PreToolUse` or `PermissionRequest` hooks gets no `allowed-tools` at all when policy sets `disableAllHooks` or `allowManagedHooksOnly`.\n\n- The coordinator no longer tells its workers that a skill grants extra tool permissions when the skill's source or plugin is not trusted under this policy.\n\n- The setting's description now says all of this.\n\n**Why**\n\nA skill or plugin placed by a user or a repository could previously hand itself tool permissions that the policy meant to keep in the administrator's hands. If you rely on a skill's `allowed-tools` under this policy, expect permission prompts for those tools, or ask your administrator to add managed rules.\n\n- Area: Permissions\n- Names: `allowManagedPermissionRulesOnly`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5"}