Claude Code's allowed-tools grants per-turn permission, not a persistent sandbox
Claude Code's allowed-tools field in skill frontmatter only pre-approves listed tools for the single turn that invokes the skill, not for the entire session. Once the user sends a follow-up message, the permission grant clears and Claude will prompt again, even if the same skill is active. The field also does not restrict other tools — it merely skips prompts for the listed ones, while all other tools remain accessible under normal permission rules. To block a tool from a skill entirely, developers should use the separate disallowed-tools field instead. For permissions that need to persist across a session or project, the recommended approach is to configure allow or deny rules in the project's permission settings.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in