You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 16da1ec
Browse filesBrowse the repository at this point in the historyBrowse files
sec-default: a settings deny rule holds over an allow or ask from a plugin the person installed (#98080)
* sec-default: a settings deny rule holds over an allow or ask from a plugin the person installed
* sec-default: the tool.check test plugins carry their verdicts in their own bodies
* sec-default: a user-tier link counts as loosening only when it answers looser than it was handed
* sec-default: the README says where the line lands in a plain -p run
* sec-default: a batch listed under prepend may hold a person's plugin, and the line says lift
* sec-default: the README and one doc comment say what the batch fix changed
Copy file name to clipboardExpand all lines: mods/README.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ source, published as it is built into the binary.
7
7
8
8
| Mod | What it does | Seated |
9
9
| --- | --- | --- |
10
-
|[`sec-default`](sec-default)| Keeps an organization's classic hooks, prompt content, managed settings and tool policy out of reach of the plugins a person installs; adds no policy of its own. | Outermost, on a machine with managed settings or for a Team or Enterprise organization, unless managed `prependPlugins` says otherwise |
10
+
|[`sec-default`](sec-default)| Keeps an organization's classic hooks, prompt content, managed settings, tool policy and deny rules out of reach of the plugins a person installs; adds no policy of its own. | Outermost, on a machine with managed settings or for a Team or Enterprise organization, unless managed `prependPlugins` says otherwise |
11
11
|[`diff`](diff)|`/diff`: the session's uncommitted changes in a pane beside the transcript, file by file with their hunks, refreshed as Claude edits files and runs commands. | Built in |
12
12
|[`telemetry`](telemetry)| Hooks `$.telemetry`'s two events (`log`, `mark`), adding the noun in the `engine.create` fold where the engine has none, so a built-in plugin can record an event as a first-party analytics row, sent in batches; refuses installed plugins; sends nothing wherever Claude Code's analytics are off. | Built in |
13
13
|[`agents-md`](agents-md)|`AGENTS.md` as project instructions, by one option: loaded where the project has no `CLAUDE.md` of its own (`claude-md-or-agents-md`, the default) or beside it (`claude-md-and-agents-md`), placed and framed exactly as the engine places `CLAUDE.md`, nested ones on a `Read`; or the project's and the person's instruction files dropped and the organization's kept (`managed-only`); or `CLAUDE.md` alone, as the engine reads it (`claude-md`). | Built in |
Copy file name to clipboardExpand all lines: mods/sec-default/README.md
+89-9Lines changed: 89 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,10 +4,11 @@ The security default for organizations. Function hooks give every plugin a
4
4
say on every event, in chain order, and the plugins a person installs sit
5
5
in the user tier, beneath the organization's prepend tier and above its
6
6
append tier. Some of what an organization sets today (its classic hooks,
7
-
its managed CLAUDE.md and rules, its settings, its MCP allowlist) was never
8
-
within a person's reach before function hooks; seated outermost, this
9
-
plugin keeps exactly those out of the user tier's reach and adds no policy
10
-
of its own. Everything else passes through untouched.
7
+
its managed CLAUDE.md and rules, its settings, its MCP allowlist, the deny
8
+
rules in force on its machines) was never within a person's reach before
9
+
function hooks; seated outermost, this plugin keeps exactly those out of the
10
+
user tier's reach and adds no policy of its own. Everything else passes
11
+
through untouched.
11
12
12
13
It has three moves and nothing else: continue past the user tier
13
14
(`next.to(e, "append")`), refuse a user-tier caller or module by name
@@ -30,12 +31,13 @@ settings it decides by.
30
31
|`tool.describe`, `command.describe`, `agent.offer`, `agent.spawn`| When the subject's pinned `e.provider.tier` is `prepend` or `append` (a policy-installed plugin, the managed folder, a policy MCP server), continue past the user tier; a subject provided by `user`, `builtin` or `core` passes. |
31
32
|`tool.register`| A caller in `prepend` or `append` continues past the user tier. A `user`-tier caller is refused by name while managed settings hold `allowedMcpServers` (set at all, empty included); otherwise it passes. |
32
33
|`tool.list`| The tools of the organization's managed MCP servers are listed as the organization's tiers listed them; every other tool as the user tier left it. With no policy to read, or a refusal from either listing, the organization's listing stands whole. |
34
+
|`tool.check`| A deny that a settings rule decided holds over the user tier: when a person's plugin loosened the verdict it was handed, the dispatch is run again past the user tier, and if that verdict is a deny naming its rule, it is the answer. See [Deny rules hold](#deny-rules-hold). Every other verdict passes as the chain left it. |
33
35
|`plugin.register`| A hooks module in the `user` tier (one a person installed, named with `--plugin-dir`, or keeps in their mods folder) is refused while managed settings set this plugin's `allowManagedModsOnly` option; otherwise it passes. Modules in `prepend`, `append` and `builtin` are never asked about. |
0 commit comments