Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.282 ·

allowManagedPermissionRulesOnly now also withholds allowed-tools from user and project skills

Under allowManagedPermissionRulesOnly, allowed-tools in untrusted skill, command and plugin frontmatter no longer grants tool permissions

Group of 3 You'll notice Internal Changes
JSON All of v2.1.282
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
Coordinator SessionsArea: what it touches
Internal ChangesKind: in v2.1.282,
ImprovementsSection of the release

What

When the managed policy setting allowManagedPermissionRulesOnly is on, the allowed-tools list in skill and command frontmatter (the header at the top of a skill file) no longer grants tool permissions unless it comes from a trusted source. Until now the setting covered permission rules from settings files and --allowedTools.

  • Ignored: allowed-tools from skills and custom commands in user, project and --add-dir sources, and from plugins adopted from a .claude-plugin manifest inside those skills directories.
  • Kept, per the setting's description: other plugins, managed skills and bundled skills. Plugins from the official skills marketplace are exempt.
  • Skills and plugin commands now look up their allowed-tools each time they run. When a grant is dropped, a warning is logged, and in text print mode a line on standard error tells you to ask an admin.
  • A plugin command whose frontmatter declares PreToolUse or PermissionRequest hooks gets no allowed-tools at all when policy sets disableAllHooks or allowManagedHooksOnly.
  • The coordinator no longer tells its workers that a skill grants extra tool permissions when the skill's source or plugin is not trusted under this policy.
  • The setting's description now says all of this.

Why

A skill or plugin placed by a user or a repository could previously hand itself tool permissions that the policy meant to keep in the administrator's hands. If you rely on a skill's allowed-tools under this policy, expect permission prompts for those tools, or ask your administrator to add managed rules.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear which skill sources Claude Code counts as trusted here.
Anthropic's release notes agreeFixed managed settings ignoring a mistyped value for boolean lock keys such as disableClaudeAiConnectors or allowManagedPermissionRulesOnly…

See this entry in the whole of v2.1.282 →

Feedback