{"version":"2.1.288","anchor":"launch-folder-settings-keys-stripped-before-merge","canonical_anchor":"launch-folder-settings-keys-stripped-before-merge","heading":"Sensitive settings from the launch folder can now be dropped before they apply","tier":"notice","area":"Settings","scope":"both","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288\/e\/launch-folder-settings-keys-stripped-before-merge","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288","markdown":"### Sensitive settings from the launch folder can now be dropped before they apply\n\nUnless a launch-folder policy allows them, settings such as enabledPlugins and modelOverrides from the launch folder are now removed\n\n**Unclear.** It is not clear what sets the policy that decides whether these settings are kept or removed.\n\n**What**\n\nThe launch folder is the folder Claude Code was started in, and it can hold its own settings. Claude Code now removes a list of sensitive settings from that folder's settings before combining them with the rest, unless a policy says they should be read as written. The list includes:\n\n- `enabledPlugins`\n\n- `allowedMcpServers`\n\n- `autoMemoryDirectory`\n\n- `modelOverrides`\n\n- `enableAllProjectMcpServers`\n\n**Why**\n\nThese settings can turn on plugins, approve MCP servers (outside tools Claude can call), move where memory is stored or redirect which model is used. Dropping them from a folder's own settings stops an untrusted folder from quietly changing them when you start Claude Code there.\n\n- Area: Settings\n- Names: `autoMemoryDirectory`, `enableAllProjectMcpServers`, `modelOverrides`\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 3\/5\n- Scope: both\n- Heads-up: yes"}