What probably matters to youSection of the release
What
Deny rules are permission rules that stop Claude Code from using certain tools or actions. A built-in plugin, cc-plugin-sec-default@builtin, now checks each tool use and puts back any deny rule that another plugin has lifted. Its options are set under pluginConfigs:
allowModsToOverrideDenyRules lets other plugins lift deny rules.
allowManagedModsOnly refuses plugins that do not come from your organization.
If the plugin cannot read its settings, it fails closed, meaning it keeps the restrictions in place.
Why
Plugins can no longer quietly weaken your deny rules unless you allow it, and organizations can limit Claude Code to their own plugins.
Read from
Names in the bundlecc-plugin-sec-default@builtinpluginConfigs
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
Confirmed sinceAnthropic's documentation has since written up cc-plugin-sec-default@builtin, on Manage mods for your organization."cc-plugin-sec-default@builtin": {plugins/mods/adminsee the edit
Confirmed sinceAnthropic's documentation has since written up pluginConfigs, on Manage Claude Code plugins for your organization.* **`allowManagedModsOnly`**: this is an option on a built-in plugin, which you set under `pluginConfigs` in managed settings. See [Stop user-installed mods from loading](/docs/en/plugins/mods/admin#stop-user-installed-mods-from-loading).plugins/orgsee the edit
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhether this built-in plugin is active by default is not known.
Anthropic's documentation agreesAnthropic's documentation has since written up pluginConfigs, on Manage Claude Code plugins for your organization.