{"version":"2.1.296","anchor":"deny-rules-can-match-additional-command-names-denymatchname","canonical_anchor":"deny-rules-can-match-additional-command-names-denymatchname","heading":"Deny rules can match extra names through denyMatchNames","tier":"notice","area":"Permissions","scope":"both","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.296\/e\/deny-rules-can-match-additional-command-names-denymatchname","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.296","markdown":"### Deny rules can match extra names through denyMatchNames\n\nA new denyMatchNames list adds extra names for deny-rule matching on prompt-type commands and feeds reserved labels for MCP-loaded tools\n\n**Unclear.** Which commands get these extra names, and what the names are, is not known.\n\n**What**\n\nA new `denyMatchNames` list gives commands and tools extra names to match against. A deny rule is a permission setting that blocks something by name.\n\n- Prompt-type commands now expose a `denyMatchNames` list. These are commands whose content is a prompt handed to Claude, which can include skills. The list joins the names already used for matching: `aliases`, `shedAliases` and `unqualifiedName`. A second helper that builds the list of match names also includes it.\n\n- Tools loaded from MCP now get a `reservedLabels` list. MCP (Model Context Protocol) is a standard way to connect Claude Code to outside tools and services. The list is built from `denyMatchNames` entries that contain a `:` and match the names of other known tools. MCP-loaded tools had no such list before.\n\n**Why**\n\nIn practice, a command, skill or tool can now be matched under more names than its usual name and aliases. Name matching is what deny rules rely on. If you write deny rules by name, keep in mind that a command or tool may now answer to extra names it did not answer to before.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5\n- Scope: both\n- Heads-up: no"}