Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.91 Home All releases olderv2.1.90 v2.1.92newer
Claude Code v2.1.91

Disable Shell Execution in Skills (Policy Setting)

What

A new disableSkillShellExecution policy/config setting that prevents inline shell execution in skills and custom slash commands from user, project, or plugin sources.

Usage: Set in your settings or policy configuration:

{
  "disableSkillShellExecution": true
}
Details
  • When enabled, shell command blocks (` `! fenced blocks and !... inline syntax) in skills are replaced with [shell command execution disabled by policy]`
  • Applies to commands from user, project, or plugin sources — not policy settings
  • Useful for organizations that want to allow skills but prevent arbitrary shell execution
Evidence

Policy gate and replacement logic (search for "disableSkillShellExecution" and "[shell command execution disabled by policy]")

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

See this entry in the whole of v2.1.91 →