You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
PluginsArea: what it touches
ImprovementsKind: in v2.1.285,
ImprovementsSection of the release
What
Plugins add features to Claude Code, and the enabledPlugins setting turns them on or off. Some built-in plugins now have new names starting with cc-plugin-, such as cc-plugin-responsive-mode. The bundled security plugin is now cc-plugin-sec-default@builtin.
To keep existing settings working:
Looking up, enabling or disabling a plugin now matches every spelling of a built-in plugin's name. Before, only an exact name match counted.
Checks for duplicate plugin names also treat the old and new spellings as the same plugin.
Writing enabledPlugins replaces older spellings of a plugin id instead of adding a second entry.
The documentation says to keep listing the security plugin as sec-default@builtin for older releases.
Why
The rename should not leave you with the same plugin listed twice, or with a plugin switched off because your settings still use its old name. Administrators who order hooks in managed settings should know that the bundled security plugin now goes by cc-plugin-sec-default@builtin.
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
Confirmed sinceAnthropic's documentation has since written up cc-plugin-sec-default@builtin, on Manage mods for your organization."cc-plugin-sec-default@builtin": {plugins/mods/adminsee the edit
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agreesAnthropic's documentation has since written up cc-plugin-sec-default@builtin, on Manage mods for your organization.