{"version":"2.1.292","anchor":"new-plugin-publish-tool-behind-tengu-copper-gazette","canonical_anchor":"new-plugin-publish-tool-behind-tengu-copper-gazette","heading":"New Publish plugin tool, blocked under HIPAA policy","tier":"notice","area":"Plugins","scope":"both","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.292\/e\/new-plugin-publish-tool-behind-tengu-copper-gazette","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.292","markdown":"### New Publish plugin tool, blocked under HIPAA policy\n\nA new Publish plugin tool can upload a plugin to claude.ai and submit it to an org library; organisations under HIPAA policy are denied it\n\n**Unclear.** Whether the publish tool is switched on by default is not stated.\n\n**What**\n\nA new tool called 'Publish plugin' is added. A plugin is a bundle of extras, such as commands or skills, that extends Claude Code. The tool is deferred, meaning it is loaded only when needed, and it is enabled only when the `tengu_copper_gazette` gate is true. Nothing has been read about that gate yet.\n\n- It uploads a plugin folder to the user's claude.ai My Uploads shelf, then submits it to the organisation's library.\n\n- Before sending, it validates the plugin, lists the files it will send, and asks the user to confirm.\n\n- It refuses to run under `--bare`, when nonessential traffic is disabled, with third-party providers, in cloud sessions, and when the user is signed out.\n\n- A new policy entry, `allow_plugin_publish`, labelled 'Publishing a plugin from Claude Code' with requirement id HIPAA-R72, is denied under the hipaa regime. If the policy cannot be looked up from cache, it also denies.\n\n**Why**\n\nMembers of an organisation may be able to share plugins with their organisation's library straight from Claude Code. Organisations covered by HIPAA rules are blocked from publishing this way.\n\n- Area: Plugins\n- Tier: You'll notice\n- Useful: 5\/5\n- Signal: 4\/5\n- Scope: both\n- Heads-up: no"}