{"version":"2.1.295","anchor":"new-claude-code-restrict-personal-config-mode-limits-what-a","canonical_anchor":"new-claude-code-restrict-personal-config-mode-limits-what-a","heading":"A new setting limits what your own skills, agents and hooks can do","tier":"use","area":"Settings","scope":"both","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295\/e\/new-claude-code-restrict-personal-config-mode-limits-what-a","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295","markdown":"### A new setting limits what your own skills, agents and hooks can do\n\nSetting CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG stops your own skills, agents and hooks from widening permissions, and makes key hooks required\n\n**What**\n\n`CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG` is an environment variable, a named value set before Claude Code starts. It can also be set in the `env` section of a settings file. When it is set, files you wrote yourself, such as your own skills, agents and hooks, cannot widen what Claude may do in the session:\n\n- Your own skills and commands cannot pre-approve tools with `allowed-tools`.\n\n- Your own agents (helpers Claude can hand work to) cannot define MCP servers or widen their permission mode.\n\n- A `WorktreeCreate` hook from your own files cannot choose the folder for the worktree, the separate working copy Claude Code makes.\n\n- Some fields in the output of your own hooks are dropped, and a note is logged.\n\n- Plugins kept inside your own skills folder load only as skills.\n\n- Launching a cloud agent is refused, with a message saying to set isolation to \"worktree\".\n\n- Hooks that carry files you uploaded to claude.ai are refused for hooks that run inside Claude Code itself.\n\nHooks are actions you set up to run at set points. While this variable is set, your own command and HTTP hooks on `PreToolUse`, `PermissionRequest`, `PreModelSwitch`, `UserPromptSubmit` and `UserPromptExpansion` must succeed. If one fails or times out, the action is blocked, and the message tells you to fix or remove the hook and tells Claude not to change it. Each restriction logs a message that names the variable. The variable is also passed on to programs Claude Code starts.\n\nSeparately, a command or HTTP hook can now set `onFailure` to `\"block\"`, so that its failure or time-out blocks the action, except on events that run when Claude stops.\n\n**Why**\n\nThis makes a locked-down session where files in your own Claude Code folder cannot grant extra permissions or quietly fail to run a check. It fits places where Claude Code runs under someone else's control and a user's own settings should not override theirs.\n\n- Area: Settings\n- Names: `CLAUDE_CODE_RESTRICT_PERSONAL_CONFIG`\n- Tier: Use it now\n- Useful: 5\/5\n- Signal: 3\/5\n- Scope: both\n- Heads-up: no"}