{"version":"2.1.284","anchor":"plugin-allowed-tools-trust-check-now-receives-plugin-provena","canonical_anchor":"plugin-allowed-tools-trust-check-now-receives-plugin-provena","heading":"Plugin tool pre-approval checks now get more detail about where a plugin came from","tier":"internal","area":"Permissions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/plugin-allowed-tools-trust-check-now-receives-plugin-provena","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Plugin tool pre-approval checks now get more detail about where a plugin came from\n\nWhen a managed policy restricts sources, the check on a plugin command's pre-approved tools now receives the plugin's attestation and origin details\n\n**Unclear.** The rule that decides which plugins pass using these new details is not known.\n\n**What**\n\nA command can list tools it is allowed to use without asking, in its `allowed-tools` field. Where an organisation's managed policy restricts which sources are trusted, Claude Code filters that list by source. For commands from plugins, the check used to get only the plugin's repository. It now also receives:\n\n- whether the plugin is officially attested\n\n- the marketplace it came from\n\n- how it was resolved from npm, if it was\n\n- its home location\n\nWhen no managed restriction is in place, all sources pass as before.\n\n**Why**\n\nUnder a managed policy, a plugin's pre-approved tools may now be kept or removed based on its attestation or marketplace origin, not just its repository.\n\n- Area: Permissions\n- Tier: Under the hood\n- Useful: 1\/5\n- Signal: 1\/5"}