{"version":"2.1.282","anchor":"skill-allow-rules-no-longer-pre-approve-names-reserved-for","canonical_anchor":"skill-allow-rules-no-longer-pre-approve-names-reserved-for","heading":"Skill allow rules no longer approve skills using names reserved for claude.ai","tier":"notice","area":"Permissions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282\/e\/skill-allow-rules-no-longer-pre-approve-names-reserved-for","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.282","markdown":"### Skill allow rules no longer approve skills using names reserved for claude.ai\n\nA `Skill(...)` allow rule no longer silently approves a skill that uses a name reserved for skills synced from your claude.ai account\n\n**Unclear.** Which name prefixes count as reserved is not settled.\n\n**What**\n\nA skill is a packaged set of instructions Claude can use, and an allow rule such as `Skill(x)` lets a skill run without asking you first. Some skill names, marked by a set prefix, are now reserved for the skills synced from your claude.ai account. A `Skill(...)` rule, including one that matches by prefix, no longer pre-approves these:\n\n- a skill that uses a reserved name but did not come from your account, for example one from a plugin\n\n- a synced skill that has been renamed, where your rule still names the old name\n\nIn both cases you are asked for approval every time, with a message explaining why no rule can pre-approve it.\n\nAlongside this, a local skill whose name collides with a synced one is filtered out, and a command not supplied by a plugin that uses a reserved name is flagged as using a name reserved for your claude.ai account.\n\nThis sits behind the `tengu_plaid_harbor` gate, whose built-in default is on, and the server can change it. With the gate off, a plain name or prefix match still allows the skill.\n\n**Why**\n\nIf you have broad `Skill(...)` allow rules, you may start seeing approval prompts for plugin skills that use names meant for your account's own skills. This stops another source from borrowing those names to run without asking.\n\n- Flag `tengu_plaid_harbor`: Not enough to say (read for one account on one subscription tier against v2.1.282; this account: no value returned, anonymous baseline: no value returned, compiled default: on) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5"}