A skill is a packaged set of instructions Claude can use, and an allow rule such as Skill(x) lets a skill run without asking you first. Some skill names, marked by a set prefix, are now reserved for the skills synced from your claude.ai account. A Skill(...) rule, including one that matches by prefix, no longer pre-approves these:
- a skill that uses a reserved name but did not come from your account, for example one from a plugin
- a synced skill that has been renamed, where your rule still names the old name
In both cases you are asked for approval every time, with a message explaining why no rule can pre-approve it.
Alongside this, a local skill whose name collides with a synced one is filtered out, and a command not supplied by a plugin that uses a reserved name is flagged as using a name reserved for your claude.ai account.
This sits behind the tengu_plaid_harbor gate, whose built-in default is on, and the server can change it. With the gate off, a plain name or prefix match still allows the skill.
If you have broad Skill(...) allow rules, you may start seeing approval prompts for plugin skills that use names meant for your account's own skills. This stops another source from borrowing those names to run without asking.
tengu_plaid_harbor Not enough to sayNothing here resolved what this flag was doing on this version, so nothing here should be read as on or off.
This account: no value returned · anonymous baseline: no value returned · compiled default in v2.1.282: on
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.282. It isn't a statement about your account. What a flag value here can and cannot tell you
Which name prefixes count as reserved is not settled.