Long or hostile text in permission prompts is now truncated and unnamed servers show a placeholder.
What's wrong with this entry?
MCP elicitation text, MCP and WebSocket tool descriptors, Bash commands, skill names and descriptions, notebook cell ids and artifact labels now go through display sanitizers with a length cap, and missing MCP server or tool names show a placeholder such as "(unnamed server)".
- The URL elicitation dialog only preselects the accept option when both the message and the URL survive sanitizing unchanged and contain no newlines; otherwise the accept handler refuses to open the URL.
- An option preview that is too long is marked withheld, and its always-allow row is dropped.
(unnamed server)
Strings lifted out of the shipped bundle, so the claim above can be checked against them.