{"version":"2.1.295","anchor":"tool-call-directory-re-check-for-mcp-serve","canonical_anchor":"tool-call-directory-re-check-for-mcp-serve","heading":"Shell commands over MCP are refused if their working folder changed after approval","tier":"notice","area":"MCP","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295\/e\/tool-call-directory-re-check-for-mcp-serve","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295","markdown":"### Shell commands over MCP are refused if their working folder changed after approval\n\nWhen Claude Code runs a shell command for an MCP client, it now refuses if the working folder was deleted, moved or replaced after the permission check\n\n**What**\n\nMCP (Model Context Protocol) is a standard way for other programs to connect to Claude Code and use its tools. When Claude Code serves a request this way and that request runs a shell command, Claude Code first checks permission to run the command in a particular working folder.\n\nClaude Code now checks again, just before starting the command, that the working folder is still the same one it checked. If the folder was deleted, moved or replaced in the meantime, the command does not run. You see a message saying Claude Code could not confirm that working directory, and you are asked to issue the command again.\n\n**Why**\n\nThis closes a gap between the moment a command is approved and the moment it runs. Without the second check, a command approved for one folder could end up running somewhere else if the folder changed in between.\n\n- Area: MCP\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: no"}