{"version":"2.1.290","anchor":"remote-session-mcp-tools-routed-through-auto-mode-classifier","canonical_anchor":"remote-session-mcp-tools-routed-through-auto-mode-classifier","heading":"Stricter approvals for MCP tools in remote sessions and on the session's desktop","tier":"notice","area":"Auto Mode","scope":"both","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/remote-session-mcp-tools-routed-through-auto-mode-classifier","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Stricter approvals for MCP tools in remote sessions and on the session's desktop\n\nMCP tools that may act on the session's desktop now ask every time, and remote-session MCP tools cannot be always-allowed\n\n**Unclear.** What the \"arbiter\" mode corresponds to for users is unclear.\n\n**What**\n\nMCP tools are tools supplied by outside servers that Claude can call. Claude Code tightens when these can run without asking you.\n\n- Some MCP tools are now marked as able to act on the session's desktop. Each call to one asks for approval, with the message \"may act on this session's desktop, so each call is reviewed; allow rules, hooks and plugins cannot approve it.\" The option to always allow it is not offered, though the automatic classifier can still approve it. A specific allowlisted server and tool pair is exempt.\n\n- In remote sessions, when an MCP tool asks for approval, the option to always allow it is not offered.\n\n- In a remote session (`CLAUDE_CODE_REMOTE` set) using the \"arbiter\" mode with `tengu_buzzing_pelican` on, a hook's approval of an MCP tool is sent to the auto-mode classifier, a check that decides whether the action is safe, instead of being final, and always-allow rules are ignored. Nothing has been read about `tengu_buzzing_pelican` yet.\n\n- The existing check tied to `tengu_cowork_auto_mode_include_allowed_write_mcp` now reports whether it applied because of server policy or because of a remote session. The flag server returned on for this site's account and for the anonymous baseline; no reading has been taken under this release.\n\n**Why**\n\nTools that could act on a desktop can no longer be waved through by a saved rule, a hook or a plugin, so you see each call. In remote sessions, a single \"always allow\" no longer covers future MCP calls. Expect more approval prompts where these tools are used.\n\n- Flag `tengu_buzzing_pelican`: Not enough to say (read for one account on one subscription tier against v2.1.290; this account: no value returned, anonymous baseline: no value returned, compiled default: off) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Flag `tengu_virtual_knuth`: Not enough to say (read for one account on one subscription tier against v2.1.290; this account: no value returned, anonymous baseline: no value returned, compiled default: off) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: Auto Mode\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 3\/5\n- Scope: both\n- Heads-up: yes"}