Policy-level tool blocking and sandbox controls debut with prompt stop hooks. Output styles deprecated—migrate to --system-prompt-file. MCP sub-agents now inherit tools correctly.
disallowedTools to custom agent definitions — part of a sustained push to make the plugin/agent system more configurable and secure across the 2.0.x series.security unlock-keychain when encountering API key errors on macOS with locked keychainallowUnsandboxedCommands sandbox setting to disable the dangerouslyDisableSandbox escape hatch at policy leveldisallowedTools field to custom agent definitions for explicit tool blocking/context would sometimes fail with "max_tokens must be greater than thinking.budget_tokens" error message--mcp-config flag to correctly override file-based MCP configurations/output-style and use --system-prompt-file, --system-prompt, --append-system-prompt, CLAUDE.md, or plugins instead