{"version":"2.1.289","anchor":"plugin-hook-sandbox-now-copies-values-leaving-the-sandbox","canonical_anchor":"plugin-hook-sandbox-now-copies-values-leaving-the-sandbox","heading":"Values leaving the plugin hook sandbox are now copied and checked","tier":"internal","area":"Plugin Hooks","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.289\/e\/plugin-hook-sandbox-now-copies-values-leaving-the-sandbox","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.289","markdown":"### Values leaving the plugin hook sandbox are now copied and checked\n\nPlugin hook values leaving the plugin's sandbox are now copied, frozen and checked as plain data, unless `isLeavingUncopied` is set\n\n**Unclear.** It is not clear what sets the option that lets values leave the sandbox uncopied.\n\n**What**\n\nPlugin hooks run in a sandbox, a walled-off space kept apart from Claude Code itself. Values passing out of that space were passed through `vmClone` only. They are now copied and checked first.\n\n- Copying: values leaving the plugin environment are copied and frozen so they can't be changed afterwards. Records, arrays, maps, errors and other values are walked and copied.\n\n- Refused values: functions, Proxies and unknown kinds are refused. Arguments that are not plain data are rejected with a message of the form \"not plain data\".\n\n- Switch: copying is skipped when the host option `isLeavingUncopied` is set. That option is turned on when a separate internal check returns false, which suggests the change is being rolled out in stages.\n\n**Why**\n\nThis hardens the boundary between plugins and Claude Code. Plugin authors should watch for it: a hook that returns functions or other non-plain values may now have them refused.\n\n- Area: Plugin Hooks\n- Tier: Under the hood\n- Useful: 2\/5\n- Signal: 3\/5\n- Scope: individual\n- Heads-up: yes"}