{"version":"2.1.284","anchor":"plugin-skill-allowed-tools-under-managed-only-policy-now-con","canonical_anchor":"plugin-skill-allowed-tools-under-managed-only-policy-now-con","heading":"Managed-only permission policy now considers where a plugin came from","tier":"notice","area":"Permissions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/plugin-skill-allowed-tools-under-managed-only-policy-now-con","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Managed-only permission policy now considers where a plugin came from\n\nUnder `allowManagedPermissionRulesOnly`, plugin skills can keep their allowed tools based on official attestation or marketplace source\n\n**What**\n\nA skill is a set of instructions a plugin adds to Claude Code, and its allowed-tools list grants it tools without asking you. When an administrator sets `allowManagedPermissionRulesOnly`, Claude Code decides whether to honour a plugin skill's allowed-tools. Before, that decision looked only at the plugin's id. It now also looks at:\n\n- Whether the plugin is officially attested\n\n- Which marketplace it came from\n\n- How it was resolved from npm, if it was\n\n- Its home location\n\nPlugins can be trusted by attestation or by marketplace source. The same details are also kept with the plugin's commands.\n\n**Why**\n\nIn tightly managed organisations, officially attested plugins or plugins from trusted marketplaces can keep the tool grants their skills rely on.\n\n- Area: Permissions\n- Names: `allowManagedPermissionRulesOnly`\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}