Fetching from the wire…
Public story · 2026-08-26 · high
The per-tool auto-approve toggles looked granular but did nothing, so anyone relying on them has been running with blanket MCP approval all along.
Why now: Cline shipped the fix in v4.1.16 on August 26.
Cline pulled the per-tool auto-approve checkboxes for MCP servers in v4.1.16, released August 26, because they never did what they looked like they did.
Anyone who ticked auto-approve for one tool on an MCP server while leaving another unchecked, a read-only lookup left off, a write tool left on, has been running with blanket approval the whole time. Auto-approval for MCP tools is controlled by a single global "Use MCP servers" toggle. The per-tool checkboxes didn't feed into that decision at all.
Cline's release notes call the checkboxes no-ops that implied a granularity the approval path never had. They don't say how long the checkboxes existed before that got noticed, or how many MCP servers ship tools risky enough for the gap to matter.
The same release fixes two other issues. Hooks were resolving their workspace from shared global state in ~/.cline instead of the current VS Code window, which breaks if you run multiple Cline windows on different projects at once. And Cline now redacts credentials embedded in git remote URLs before they reach the model, closing a path where a token pasted into a git remote URL could end up in a prompt.
Each link below shares sources, entities, or timing with this story.
v4.1.16 and SDK v0.0.80, both August 26, strip credentials from git remote URLs included in the system prompt. If your remote is that token was going to the model on every task (GitHub). The same releases fix hooks resolving their workspace from shared global state in ~/.cline...
Before v4.1.15 on August 23, it only applied to tools also opted in individually, so flipping it appeared to do nothing. Anyone who left it on assuming it was inert has just widened their unattended tool surface across every connected server. (GitHub) Same release train fixed...
A spec is a press release until someone who didn't write it implements it. GitHub made Agent Plugins 1.0 generally available on August 12 across VS Code, Copilot CLI, the Copilot SDK, and the Copilot app on all plans. The spec, published August 6, was co-authored by AWS, Anysp...
Across v4.1.11 through v4.1.14 (August 21-23), Cline began hiding MCP marketplace entries when remote config disables the marketplace and restricting them to allowedMCPServers under an allowlist. The interesting bug took two releases to fix: for custom OpenAI-compatible models...
Roo Code announced it will archive its VS Code extension repo on May 15 and merge back into Cline, the project it originally forked from. CEO Matt Rubens said the team needs to "constantly destroy and recreate to keep up with what's newly possible." Translation: the extension...
A Chinese lab shipped a runtime that manages two American coding agents as subagents, and it went from repo creation to 145,439 stars in four days. deepseek-ai/deepseek-harness published dsh-v0.1.0-rc.7 at 12:01 UTC today, its first tagged release since the repo appeared on Au...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.