Follow Discord
Sweep 01 Oct 2026 · 17:27Z Build v2.1.287 508 read Stable v2.1.285 Latest v2.1.287 Next v2.1.287 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.286 ·

Built-in security plugin keeps deny rules in force over other plugins

A built-in plugin restores deny rules that other plugins lift, and can refuse plugins that did not come from your organization

Use it now Notable New Features
JSON All of v2.1.286
Use it nowTier: how much it should matter to you
5Useful: my rating, 1 to 5
4Signal: worth watching, 1 to 5
PermissionsArea: what it touches
New FeaturesKind: in v2.1.286,
What probably matters to youSection of the release
What

Deny rules are permission rules that stop Claude Code from using certain tools or actions. A built-in plugin, cc-plugin-sec-default@builtin, now checks each tool use and puts back any deny rule that another plugin has lifted. Its options are set under pluginConfigs:

  • allowModsToOverrideDenyRules lets other plugins lift deny rules.
  • allowManagedModsOnly refuses plugins that do not come from your organization.

If the plugin cannot read its settings, it fails closed, meaning it keeps the restrictions in place.

Why

Plugins can no longer quietly weaken your deny rules unless you allow it, and organizations can limit Claude Code to their own plugins.

Read from
Names in the bundlecc-plugin-sec-default@builtinpluginConfigs
What the documentation says
Since it was published

The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.

Confirmed since Anthropic's documentation has since written up cc-plugin-sec-default@builtin, on Manage mods for your organization. "cc-plugin-sec-default@builtin": { plugins/mods/admin see the edit
Confirmed since Anthropic's documentation has since written up pluginConfigs, on Manage Claude Code plugins for your organization. * **`allowManagedModsOnly`**: this is an option on a built-in plugin, which you set under `pluginConfigs` in managed settings. See [Stop user-installed mods from loading](/docs/en/plugins/mods/admin#stop-user-installed-mods-from-loading). plugins/org see the edit
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhether this built-in plugin is active by default is not known.
Anthropic's documentation agreesAnthropic's documentation has since written up pluginConfigs, on Manage Claude Code plugins for your organization.

See this entry in the whole of v2.1.286 →

Feedback