{"version":"2.1.290","anchor":"remote-session-mcp-calls-engine-decision-wins-over-plugin-h","canonical_anchor":"remote-session-mcp-calls-engine-decision-wins-over-plugin-h","heading":"Plugins can no longer loosen permissions for MCP calls in remote sessions","tier":"notice","area":"Permissions","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/remote-session-mcp-calls-engine-decision-wins-over-plugin-h","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Plugins can no longer loosen permissions for MCP calls in remote sessions\n\nFor MCP tool calls in remote sessions, Claude Code now keeps its own stricter decision over a plugin's looser one\n\n**Unclear.** What the switch controlling this defaults to is not clear.\n\n**What**\n\nMCP tools are tools added to Claude Code from outside, through the Model Context Protocol. Plugins can weigh in on whether such a tool may be used. For MCP calls made from a remote session, Claude Code now compares the plugin's decision with its own. When its own decision is stricter, it ignores the plugin's and records that it did.\n\n**Why**\n\nThis tightens permissions for MCP tools used in remote sessions, so a plugin cannot allow something Claude Code itself would block.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: yes"}