Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.295 ·

Auto mode can pick up aliased MCP tools so the safety check covers them

Behind a switch that is off by default, auto mode registers tools reached through toolAliases or warns when an allow rule would skip its check

Nothing to try yet In Development
JSON All of v2.1.295
Nothing to try yetTier: how much it should matter to you
2Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
Auto ModeArea: what it touches
In DevelopmentKind: in v2.1.295,
In DevelopmentSection of the release

Unclear It is not clear how registering an aliased tool changes the way the classifier checks its calls.

What

Auto mode is a permission mode in which Claude Code uses a classifier, an automatic safety check, to decide whether each tool call can run without asking you. Claude Code now has a step that looks at your toolAliases, which are alternative names that point at a tool.

  • An alias that points at an MCP tool name (an MCP tool comes from an external server and is named in the form mcp__server__tool) gets that tool registered.
  • An alias that points at a tool from an SDK-created MCP server running with CLAUDE_AGENT_SDK_MCP_NO_PREFIX, which drops the mcp__<server>__ prefix from tool names, also gets the tool registered.
  • For any other alias, Claude Code logs a warning that an allow rule for that tool still runs its calls without the classifier's check.

This step is off unless it is switched on remotely.

Why

Tools reached through an alias could slip past the auto mode check. The warning tells you when an allow rule you wrote means a tool's calls are not being checked.

Read from
Names in the bundletoolAliases
Feature flag
tengu_sorted_zebra Not enough to say

Nothing here resolved what this flag was doing on this version, so nothing here should be read as on or off.

This account: no value returned · anonymous baseline: no value returned · compiled default in v2.1.295: off

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

Read once, for one account on one subscription tier, against v2.1.295. It isn't a statement about your account. What a flag value here can and cannot tell you

What the documentation says
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear how registering an aliased tool changes the way the classifier checks its calls.
Anthropic's release notes agreeImproved the status shown in Remote Control, claude.ai and the desktop app for a session waiting on a permission prompt to name an MCP tool…
The name it cites is new in this buildNew in this build: tengu_sorted_zebra

See this entry in the whole of v2.1.295 →

Feedback