Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.290 ·

Names with a slash passed to served MCP tools are checked first

A call that gives one of the app's own MCP tools a name containing a slash is now checked before it runs, with its own explanation

You'll notice Improvements
JSON All of v2.1.290
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
MCPArea: what it touches
ImprovementsKind: in v2.1.290,
ImprovementsSection of the release

Unclear It is not clear whether this check runs in every case or only under certain conditions.

What

MCP (Model Context Protocol) is the standard way programs offer Claude tools. When a call gives one of the app's own MCP tools a name containing a slash or backslash, Claude Code now checks the call before it runs and explains why in the permission prompt. The explanation reads: "This call gives one of [the app]'s own MCP tools a name with a slash in it, so it is checked before it runs."

Names that are clearly a full path, a home-folder path, a variable or a web address are not matched by this rule. They already had their own explanations.

Why

Relative paths, such as src/file.txt, passed to these tools now lead to a check and a clear reason, so they cannot slip through without notice.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear whether this check runs in every case or only under certain conditions.

See this entry in the whole of v2.1.290 →

Feedback