{"version":"2.1.290","anchor":"mcp-relative-path-names-in-tool-input-are-now-judged-and-can","canonical_anchor":"mcp-relative-path-names-in-tool-input-are-now-judged-and-can","heading":"Path-safety checks now judge relative names in MCP tool input and more kinds of risky paths","tier":"notice","area":"MCP","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/mcp-relative-path-names-in-tool-input-are-now-judged-and-can","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Path-safety checks now judge relative names in MCP tool input and more kinds of risky paths\n\nThe path-safety check now resolves relative file names given to MCP tools, considers mount points, and describes \/proc links, overlong paths and unknown home folders\n\n**Unclear.** It is not clear what switches the handling of relative names on, or whether it applies in every session.\n\n**What**\n\nBefore Claude reads or uses a file path, Claude Code checks whether that path is safe and may ask you first or refuse. This release widens that check.\n\n- MCP tools are tools that outside servers add to Claude Code. File names in their input that look relative, such as `dir\/file`, are now resolved against the working directory, the folder Claude Code is running in. They are then checked like any other path. The check can return a new `relative_path` result and attach a `why` explanation when it decides to ask you. Before, it returned only `ask`, `web_address` or deny.\n\n- Mount points, places where another drive or volume is attached, are now taken into account, so paths on mounted volumes are checked. On macOS, `\/volumes` is now guarded.\n\n- The list of path descriptions gains three new kinds: magic links, which are paths through an open file descriptor or a process's `\/proc` link; paths too long to open; and paths in a home folder the session does not know about.\n\n**Why**\n\nMore kinds of paths can now lead to a permission prompt or a refusal, including relative names passed to MCP tools and `\/proc` or file-descriptor paths. Expect prompts in some cases that went through before.\n\n- Area: MCP\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: yes"}