What
When a program drives Claude Code through the SDK, the library for running it from your own code, permission prompts arrive as can_use_tool requests. The program answers them through its canUseTool callback. These requests gain two new optional fields, both marked internal:
server_prompt: a marker the session service (the cloud side of a session) puts on permission asks it worded itself. Hosts still show the tool name and input whatever it says.computer_folder: an object with apathand acomputer_name, naming a folder on one of the person's computers.
Both fields are documented as untrusted text to escape before display. Claude Code checks their shape, and a malformed computer_folder is removed and logged. Both are passed to canUseTool as serverPrompt and computerFolder, together with requires_user_interaction as requiresUserInteraction. Claude Code itself never sets these fields; only the session service does.
Why
If you build on the SDK, your permission prompts can now show which folder on which computer a request is about. Treat both fields as untrusted text, and escape them before showing them.
The finding does not say what each of the three fields describes or when Claude Code fills them in.