{"version":"2.1.288","anchor":"plugin-network-gating-now-also-covers-claude-code-eval-confi","canonical_anchor":"plugin-network-gating-now-also-covers-claude-code-eval-confi","heading":"Plugins lose network access in confined sessions","tier":"notice","area":"Plugins","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288\/e\/plugin-network-gating-now-also-covers-claude-code-eval-confi","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288","markdown":"### Plugins lose network access in confined sessions\n\nPlugins are now refused network access when `CLAUDE_CODE_EVAL_CONFINED` is set, and a message says the session's credential is withheld\n\n**Unclear.** Which sessions count as being in the mode that gets the credential-withheld message is not known.\n\n**What**\n\nThe check that decides whether a plugin may use the network has been rewritten. It now refuses network access, saying nonessential network traffic is disabled for this session, in more cases:\n\n- `CLAUDE_CODE_EVAL_CONFINED` is set to true.\n\n- The session is in a particular mode and the plugin's name or marketplace is missing or cannot be resolved.\n\nIn that mode, Claude Code can also say that the session's credential is withheld. Before, plugins were refused only when nonessential network traffic was turned off.\n\n**Why**\n\nConfined sessions now keep plugins off the network and keep the session's credential away from them.\n\n- Area: Plugins\n- Names: `CLAUDE_CODE_EVAL_CONFINED`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: yes"}