You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.284,
ImprovementsSection of the release
What
allowManagedPermissionRulesOnly is a managed setting, one an organization's administrators set, that makes managed settings the only source of permission rules. A plugin can declare allowed-tools, a list of tools it may use without asking. The setting's description now says that under this setting a plugin keeps its allowed-tools only if it came through an admin-backed channel:
registry-pinned plugins installed directly from npm
Every other plugin's allowed-tools are ignored. Before, the description said only plugins picked up from a plugin manifest inside user, project or added skills folders lost theirs.
Why
Organizations using this lockdown may find that plugins from ordinary marketplaces stop getting their tool permissions unless an admin vouches for where they came from.