{"version":"2.1.286","anchor":"built-in-security-plugin-deny-rules-hold-over-plugins-mana","canonical_anchor":"built-in-security-plugin-deny-rules-hold-over-plugins-mana","heading":"Built-in security plugin keeps deny rules in force over other plugins","tier":"use","area":"Permissions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286\/e\/built-in-security-plugin-deny-rules-hold-over-plugins-mana","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286","markdown":"### Built-in security plugin keeps deny rules in force over other plugins\n\nA built-in plugin restores deny rules that other plugins lift, and can refuse plugins that did not come from your organization\n\n**Unclear.** Whether this built-in plugin is active by default is not known.\n\n**What**\n\nDeny rules are permission rules that stop Claude Code from using certain tools or actions. A built-in plugin, `cc-plugin-sec-default@builtin`, now checks each tool use and puts back any deny rule that another plugin has lifted. Its options are set under `pluginConfigs`:\n\n- `allowModsToOverrideDenyRules` lets other plugins lift deny rules.\n\n- `allowManagedModsOnly` refuses plugins that do not come from your organization.\n\nIf the plugin cannot read its settings, it fails closed, meaning it keeps the restrictions in place.\n\n**Why**\n\nPlugins can no longer quietly weaken your deny rules unless you allow it, and organizations can limit Claude Code to their own plugins.\n\n- Area: Permissions\n- Names: `cc-plugin-sec-default@builtin`, `pluginConfigs`\n- Tier: Use it now\n- Useful: 5\/5\n- Signal: 4\/5"}