Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.222 Home All releases olderv2.1.221 v2.1.223newer

Destructive MCP tools can be included in remote auto-mode

Not switched on
Useful3 Signal4
Permissions Notable not in their notes

Destructive MCP tools could stop skipping permission prompts in remote auto mode, but that is off.

A check forcing prompts for destructive MCP tools in remote auto mode is gated on tengu_remote_auto_mode_include_destructive_mcp, false in source.

Feature flag
tengu_remote_auto_mode_include_destructive_mcp Off in both readings

The flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.

This account: off · anonymous baseline: off · compiled default in v2.1.222: on

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

Read once, for one account on one subscription tier, against v2.1.222. It isn't a statement about your account. What a flag value here can and cannot tell you

tengu_remote_auto_mode_include_destructive_mcp
What

A new predicate combines the auto/plan remote mode check with a tool's isDestructive result, so destructive MCP tools still get a permission prompt. It is off in this build.

Details
  • When on, an MCP ask-override no longer exempts destructive tools from the prompt.
  • Gated on tengu_remote_auto_mode_include_destructive_mcp, fallback value in source is false.
  • A new mcpServerAskOverride field was added to four permission telemetry payloads.
Evidence

tengu_remote_auto_mode_include_destructive_mcp

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.222 →