Claude Code has gained an internal capability called mcp_read_resource that lets it read a resource from an MCP server (Model Context Protocol, a standard that lets Claude Code connect to external tools and data sources). This works through the resources/read request, but only for resources whose address (URI) starts with ui:// — requests for any other scheme are rejected.
Before returning content, the capability runs several checks:
- whether the MCP server is actually connected
- whether the server has been disabled
- whether a policy is blocking the request
- whether the resource is within an allowed size limit
This gives Claude Code a controlled way to pull in resources exposed by MCP servers, but keeps it scoped tightly to ui:// resources rather than opening up arbitrary resource reading, and the added checks stop it from reading from servers that are disabled, blocked, disconnected, or from resources that are too large.
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
All external origins are blocked by default. Declare the origins each `ui://` resource needs through `_meta.ui.csp`:connectors/building/mcp-apps/design-guidelines see the edit
The finding does not say what ui:// resources are used for or what kind of content they contain.
Anthropic's documentation has since written up ui://, on Design guidelines.