Fetching from the wire…
Public story · 2026-08-24 · high
Before v4.1.15, the setting only mattered if you'd separately approved each tool; updating widens unattended access for anyone who'd flipped it on.
Why now: Both fixes arrived in the same August 23 release, so updating for one pulls in the other whether you meant to or not.
Cline released version 4.1.15 on August 23, fixing a bug in its "Use MCP servers" toggle that had made the setting nearly pointless. Before this build, checking the box only mattered if you'd also approved each MCP tool individually, so most people who turned it on saw no change in behavior and assumed it did nothing.
Cline's v4.1.15 release notes say the toggle alone auto-approves every MCP tool call across every connected server in this version, with no per-tool opt-in required. Anyone who left the box checked because it seemed inert inherits a wider unattended tool surface after updating to v4.1.15.
MCP servers can reach file systems, shell commands, and third-party APIs, depending on what's connected. A setting that goes from mostly decorative to granting everything, with no security-specific callout, is easy to miss inside a general bug-fix release.
The same build fixed a second, unrelated issue. For custom OpenAI-compatible models, Cline had been inferring the model's capability list and stripping every tool from the request without saying so. Version 4.1.15's release notes list this alongside the MCP fix, giving a custom model integration that seemed to get worse over recent releases a documented explanation.
Neither bug was cosmetic. One made a permission toggle lie about what it approved. The other made a model lose tools it was supposed to have, with no error to explain why.
People running Cline with MCP servers connected should open the toggle's current setting and confirm what it's approving before leaving it running unattended.
Each link below shares sources, entities, or timing with this story.
v4.1.16, also August 26, hides them because "the per-tool checkboxes were no-ops that implied granularity the approval path does not have." MCP auto-approval is governed entirely by the global "Use MCP servers" toggle. Anyone who ticked auto-approve for a read-only tool while...
Across v4.1.11 through v4.1.14 (August 21-23), Cline began hiding MCP marketplace entries when remote config disables the marketplace and restricting them to allowedMCPServers under an allowlist. The interesting bug took two releases to fix: for custom OpenAI-compatible models...
Three things happened this month that only make sense together. Agent Plugins 1.0 shipped co-signed by six competitors: AWS, Anysphere, Microsoft, OpenAI, Vercel and Google (GitHub Changelog). It makes skills-plus-MCP bundles portable across clients. OpenAI's August 11 Codex c...
OpenAI Devs announced on August 26 that WebMCP works in the ChatGPT desktop app's built-in browser and in ChatGPT Sites, so ChatGPT and Codex can call a site's declared tools directly. WebMCP is an experimental web standard adding navigator.modelContext to the browser, letting...
A spec is a press release until someone who didn't write it implements it. GitHub made Agent Plugins 1.0 generally available on August 12 across VS Code, Copilot CLI, the Copilot SDK, and the Copilot app on all plans. The spec, published August 6, was co-authored by AWS, Anysp...
If you wrote an MCP server before July, it's on a protocol shape the maintainers have already removed. Not deprecated-with-a-migration-window. Removed from the spec. MCP lead maintainers David Soria Parra and Den Delimarsky published an updated roadmap on August 22, and the re...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.