Skill and config passthrough names were checked against the managed-credential policy only when accepted. A plugin adapter registering later claims <PREFIX>_*_SECRET, but is_env_passthrough() and get_all_passthrough() kept returning the stale approval, so terminal, background and execute_code children (and scope-only additions) still received the secret. Both now re-apply the refusal when the allowlist is consumed.