What
Frontmatter is the settings block at the top of a skill or agent file, between two --- lines. Skills are reusable instructions Claude can load, and agents are helpers with their own instructions. The frontmatter reader now has an untrusted option. When it is set, the reader refuses frontmatter that is too long, too nested, or may hold a YAML anchor (a shortcut that repeats one part of the file elsewhere), and reports a parse error.
- Skills from MCP servers are read with
untrusted: true. If the frontmatter is refused, the skill is skipped and a message says the frontmatter was not read and the skill was skipped. - Skills from memory stores are read with
untrusted: true. If the frontmatter is refused, the skill is skipped and the log saysfrontmatter was not read. - Plugin agents are read with
untrusted, and loading fails with an error if the frontmatter is refused. Before, plugin agent frontmatter was read without limits. - The reader also skips its pattern match when there is no second
---line.
Why
Skills and agents from remote MCP servers, shared memory stores and plugins come from outside your own setup. Oversized or malformed frontmatter from them is now refused instead of loaded, so a skill or agent may stop appearing if its frontmatter breaks these limits.
It is not clear what reading a header as untrusted changes beyond skipping skills whose header fails.