{"version":"2.1.288","anchor":"tool-hook-sec-default-plugin-tamper-check-and-per-event-coun","canonical_anchor":"tool-hook-sec-default-plugin-tamper-check-and-per-event-coun","heading":"Claude Code checks that a built-in plugin does not alter tool descriptions","tier":"internal","area":"Plugins","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288\/e\/tool-hook-sec-default-plugin-tamper-check-and-per-event-coun","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288","markdown":"### Claude Code checks that a built-in plugin does not alter tool descriptions\n\nClaude Code now logs and reports an error if its built-in sec-default plugin changes a tool's description or whether it is deferred\n\n**Unclear.** It is not clear what the new per-event input to the hook check changes in practice.\n\n**What**\n\nPlugins can hook into the step where Claude Code describes each tool to Claude. The built-in sec-default plugin is meant only to pass that step along unchanged.\n\nClaude Code now checks that the sec-default plugin did not change a tool's description or whether the tool is deferred (held back until needed). If it did, Claude Code logs an error and reports it. Previously a hook could change a description with no check.\n\nThe check that decides whether a hook runs now also takes the kind of event into account.\n\n**Why**\n\nThis guards the plugin system: a built-in plugin that unexpectedly rewrites how tools are described is now caught and recorded.\n\n- Area: Plugins\n- Tier: Under the hood\n- Useful: 1\/5\n- Signal: 3\/5\n- Scope: individual\n- Heads-up: no"}