{"version":"2.1.280","anchor":"new-mcp-read-resource-capability-restricted-to-ui-uris","canonical_anchor":"new-mcp-read-resource-capability-restricted-to-ui-uris","heading":"New mcp_read_resource capability restricted to ui:\/\/ URIs","tier":"use","area":"MCP","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280\/e\/new-mcp-read-resource-capability-restricted-to-ui-uris","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280","markdown":"### New mcp_read_resource capability restricted to ui:\/\/ URIs\n\nClaude Code can now read MCP resources, but only ones using the ui:\/\/ URI scheme\n\n**Unclear.** The finding does not say what ui:\/\/ resources are used for or what kind of content they contain.\n\n**What**\n\nClaude Code has gained an internal capability called `mcp_read_resource` that lets it read a resource from an MCP server (Model Context Protocol, a standard that lets Claude Code connect to external tools and data sources). This works through the `resources\/read` request, but only for resources whose address (URI) starts with `ui:\/\/` \u2014 requests for any other scheme are rejected.\n\nBefore returning content, the capability runs several checks:\n\n- whether the MCP server is actually connected\n\n- whether the server has been disabled\n\n- whether a policy is blocking the request\n\n- whether the resource is within an allowed size limit\n\n**Why**\n\nThis gives Claude Code a controlled way to pull in resources exposed by MCP servers, but keeps it scoped tightly to `ui:\/\/` resources rather than opening up arbitrary resource reading, and the added checks stop it from reading from servers that are disabled, blocked, disconnected, or from resources that are too large.\n\n- Area: MCP\n- Names: `mcp_read_resource`, `ui:\/\/`\n- Tier: Use it now\n- Useful: 3\/5\n- Signal: 2\/5"}