{"version":"2.1.295","anchor":"auto-mode-resolves-toolaliases-for-mcp-tools-behind-tengu-so","canonical_anchor":"auto-mode-resolves-toolaliases-for-mcp-tools-behind-tengu-so","heading":"Auto mode can pick up aliased MCP tools so the safety check covers them","tier":"soon","area":"Auto Mode","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295\/e\/auto-mode-resolves-toolaliases-for-mcp-tools-behind-tengu-so","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295","markdown":"### Auto mode can pick up aliased MCP tools so the safety check covers them\n\nBehind a switch that is off by default, auto mode registers tools reached through `toolAliases` or warns when an allow rule would skip its check\n\n**Unclear.** It is not clear how registering an aliased tool changes the way the classifier checks its calls.\n\n**What**\n\nAuto mode is a permission mode in which Claude Code uses a classifier, an automatic safety check, to decide whether each tool call can run without asking you. Claude Code now has a step that looks at your `toolAliases`, which are alternative names that point at a tool.\n\n- An alias that points at an MCP tool name (an MCP tool comes from an external server and is named in the form `mcp__server__tool`) gets that tool registered.\n\n- An alias that points at a tool from an SDK-created MCP server running with `CLAUDE_AGENT_SDK_MCP_NO_PREFIX`, which drops the `mcp__<server>__` prefix from tool names, also gets the tool registered.\n\n- For any other alias, Claude Code logs a warning that an allow rule for that tool still runs its calls without the classifier's check.\n\nThis step is off unless it is switched on remotely.\n\n**Why**\n\nTools reached through an alias could slip past the auto mode check. The warning tells you when an allow rule you wrote means a tool's calls are not being checked.\n\n- Flag `tengu_sorted_zebra`: Not enough to say (read for one account on one subscription tier against v2.1.295; this account: no value returned, anonymous baseline: no value returned, compiled default: off) These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.\n- Area: Auto Mode\n- Names: `toolAliases`\n- Tier: Nothing to try yet\n- Useful: 2\/5\n- Signal: 3\/5\n- Scope: individual\n- Heads-up: no\n- Present in the build but not switched on"}