Follow Discord
Sweep 28 Sep 2026 · 18:16Z Build v2.1.284 505 read Stable v2.1.277 Latest v2.1.284 Next v2.1.284 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.284 ·

Plugin tool pre-approval checks now get more detail about where a plugin came from

When a managed policy restricts sources, the check on a plugin command's pre-approved tools now receives the plugin's attestation and origin details

Under the hood Internal Changes
JSON All of v2.1.284
Under the hoodTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
Internal ChangesKind: in v2.1.284,
Internal ChangesSection of the release
What

A command can list tools it is allowed to use without asking, in its allowed-tools field. Where an organisation's managed policy restricts which sources are trusted, Claude Code filters that list by source. For commands from plugins, the check used to get only the plugin's repository. It now also receives:

  • whether the plugin is officially attested
  • the marketplace it came from
  • how it was resolved from npm, if it was
  • its home location

When no managed restriction is in place, all sources pass as before.

Why

Under a managed policy, a plugin's pre-approved tools may now be kept or removed based on its attestation or marketplace origin, not just its repository.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe rule that decides which plugins pass using these new details is not known.
Anthropic's release notes agreeFixed plugins from marketplaces, claude.ai and npm pre-approving their own tools via allowed-tools under managed…

See this entry in the whole of v2.1.284 →

Feedback