What
When the managed policy setting allowManagedPermissionRulesOnly is on, the allowed-tools list in skill and command frontmatter (the header at the top of a skill file) no longer grants tool permissions unless it comes from a trusted source. Until now the setting covered permission rules from settings files and --allowedTools.
- Ignored:
allowed-toolsfrom skills and custom commands in user, project and--add-dirsources, and from plugins adopted from a.claude-pluginmanifest inside those skills directories. - Kept, per the setting's description: other plugins, managed skills and bundled skills. Plugins from the official skills marketplace are exempt.
- Skills and plugin commands now look up their
allowed-toolseach time they run. When a grant is dropped, a warning is logged, and in text print mode a line on standard error tells you to ask an admin. - A plugin command whose frontmatter declares
PreToolUseorPermissionRequesthooks gets noallowed-toolsat all when policy setsdisableAllHooksorallowManagedHooksOnly. - The coordinator no longer tells its workers that a skill grants extra tool permissions when the skill's source or plugin is not trusted under this policy.
- The setting's description now says all of this.
Why
A skill or plugin placed by a user or a repository could previously hand itself tool permissions that the policy meant to keep in the administrator's hands. If you rely on a skill's allowed-tools under this policy, expect permission prompts for those tools, or ask your administrator to add managed rules.
It is not clear which skill sources Claude Code counts as trusted here.
Fixed managed settings ignoring a mistyped value for boolean lock keys such as disableClaudeAiConnectors or allowManagedPermissionRulesOnly…