{"version":"2.1.292","anchor":"workflow-agent-spawns-now-go-through-a-pluginhook-that-can","canonical_anchor":"workflow-agent-spawns-now-go-through-a-pluginhook-that-can","heading":"Plugins can now refuse to let a workflow start an agent","tier":"notice","area":"Workflows","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.292\/e\/workflow-agent-spawns-now-go-through-a-pluginhook-that-can","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.292","markdown":"### Plugins can now refuse to let a workflow start an agent\n\nWhen a workflow starts an agent, a plugin hook can now refuse it, and the workflow stops with a \"denied by a plugin\" error\n\n**Unclear.** Which hook event a plugin must handle to refuse a workflow agent is not shown.\n\n**What**\n\nA workflow can start agents, separate Claude instances that each handle part of the job. Starting one now goes through a hook first. A hook is a script or plugin that runs at set points in Claude Code. If the hook refuses, the agent is not started and the workflow fails with an error that begins \"Workflow agent spawn denied by a plugin\".\n\nFor workflow agents, refusing is the only thing a hook can do. Any other fields the hook returns are ignored.\n\n**Why**\n\nPlugin authors can block workflow agents from launching, which gives them control over what a workflow is allowed to start.\n\n- Flag `tengu_workflow_schema_lint_enforce`: Not enough to say (read for one account on one subscription tier against v2.1.292; this account: no value returned, anonymous baseline: no value returned, compiled default: on) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: Workflows\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 3\/5\n- Scope: individual\n- Heads-up: no"}