Follow Discord
Sweep 28 Sep 2026 · 18:16Z Build v2.1.284 505 read Stable v2.1.277 Latest v2.1.284 Next v2.1.284 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.284 ·

Managed-only permission policy now considers where a plugin came from

Under allowManagedPermissionRulesOnly, plugin skills can keep their allowed tools based on official attestation or marketplace source

You'll notice Improvements
JSON All of v2.1.284
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.284,
ImprovementsSection of the release
What

A skill is a set of instructions a plugin adds to Claude Code, and its allowed-tools list grants it tools without asking you. When an administrator sets allowManagedPermissionRulesOnly, Claude Code decides whether to honour a plugin skill's allowed-tools. Before, that decision looked only at the plugin's id. It now also looks at:

  • Whether the plugin is officially attested
  • Which marketplace it came from
  • How it was resolved from npm, if it was
  • Its home location

Plugins can be trusted by attestation or by marketplace source. The same details are also kept with the plugin's commands.

Why

In tightly managed organisations, officially attested plugins or plugins from trusted marketplaces can keep the tool grants their skills rely on.

Read from
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's release notes agreeFixed plugins from marketplaces, claude.ai and npm pre-approving their own tools via allowed-tools under managed…

See this entry in the whole of v2.1.284 →

Feedback