Skip to content

sec-default: an organization's ceiling on a tool holds over the plugins a person installs - #99540

Open
poteat wants to merge 1 commit into
mainfrom
poteat/sec-default-ceiling-hold
Open

poteat wants to merge 1 commit into
mainfrom
poteat/sec-default-ceiling-hold

Conversation

@poteat

@poteat poteat commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Summary

TLDR: The policy mod holds an organization's ceiling on a tool, and every hook of it that decides carries a .catch.

An organization can require approval for a connector's tool. Seated, the policy mod now holds that ceiling over the plugins a person installs, as it holds a deny rule.

Notes

Hook What changes
tool.check When the chain's answer is more permissive than the question's ceiling, the dispatch is run once more past the user tier, and a stricter verdict there is the answer. The person is told once for each plugin. No option lifts it.
ui.log A line from a caller in prepend or append, this mod's own included, continues past the user tier. What a person's plugins, the built-ins and the engine log is theirs to hook as before.
classic.*, settings.read, tool.describe, command.describe, agent.offer, agent.spawn, tool.register, tool.list Each carries a .catch that decides as its hook does. None depends on a call on $ succeeding: a policy read that rejects or throws counts as a policy in force.
plugin.register, tool.check Their .catch handlers are named functions with tests of their own; a line that cannot be logged changes no answer.

mods/types/claude-code.d.ts names ceiling on tool.check's input and result. The engine sets it from the tool and pins it; a hook's own is dropped.

The five hooks that only pass prompt content and attribution text over the user tier carry no .catch, and the README says so.

Test Plan

  • claude plugin test mods/sec-default: 107 pass, 0 fail (57 before)
  • each new .catch deleted alone, and each replaced by next(e) alone: at least one case fails every time
  • the other mods in this tree pass as before, and the mods typecheck
  • claude plugin validate mods/sec-default lists the gating hooks with their .catch

…ns a person installs

An organization can require approval for a connector's tool; the engine
names that on tool.check as the question's ceiling. Seated, the policy mod
holds it over the user tier as it holds a deny rule: an answer more
permissive than the ceiling is put to the run that leaves the user tier
out, and a stricter verdict there is the answer.

What an organization's plugin logs continues past the user tier, this
mod's own lines included.

Every hook that decides carries a .catch that decides as its hook does and
depends on no call on $ succeeding.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant