Destructive MCP tools can be included in remote auto-mode#
Destructive MCP tools could stop skipping permission prompts in remote auto mode, but that is off.
A check forcing prompts for destructive MCP tools in remote auto mode is gated on tengu_remote_auto_mode_include_destructive_mcp, false in source.
tengu_remote_auto_mode_include_destructive_mcp Off in both readingsThe flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.
This account: off · anonymous baseline: off · compiled default in v2.1.222: on
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.222. It isn't a statement about your account. What a flag value here can and cannot tell you
What's wrong with this entry?
A new predicate combines the auto/plan remote mode check with a tool's isDestructive result, so destructive MCP tools still get a permission prompt. It is off in this build.
- When on, an MCP ask-override no longer exempts destructive tools from the prompt.
- Gated on tengu_remote_auto_mode_include_destructive_mcp, fallback value in source is false.
- A new mcpServerAskOverride field was added to four permission telemetry payloads.
tengu_remote_auto_mode_include_destructive_mcp
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.221
Auto mode exit message is tailored, and subagents no longer get it
Both mention auto mode
-
v2.1.229
Auto-mode setup confirmation is now a single keyboard form
Both mention auto mode
-
v2.1.229
Auto-mode setup wizard reduced to one screen
Both mention auto mode