This release is mostly about project MCP servers being less annoying and less fragile. If you work across git worktrees, approving a project's servers once now covers all of them, so a fresh worktree stops asking again. The approval prompt also no longer vanishes after /reload or when another extension takes over the editor, a bug that could leave MCP stuck and slow every prompt by up to 30 seconds. When a server does fail to connect, the agent now sees the real error, and config files the adapter can't read are left alone instead of being overwritten.
Highlights
- Approve a project's MCP servers once and every git worktree of that repository uses the same approval.
- The approval prompt stays up until you answer it, so MCP no longer gets stuck starting after
/reloador when another extension replaces the editor. - When a server can't connect, the agent sees the actual error instead of just "failed".
- Config files saved with a Windows byte order mark now load, and a config file the adapter can't parse is never overwritten.
- A dependency update fixes a high-severity denial-of-service bug in TOML config parsing.
Changelog
Highlights
- Approving a project's MCP servers once now covers every git worktree of that repository, so new worktrees stop asking again.
- The project-server approval prompt no longer disappears after
/reloador when another extension takes over the editor. Before, that could leave MCP stuck starting and add up to 30 seconds to every prompt. - When a server can't connect, the agent now sees the actual error instead of just "failed".
- Config files are safer: files saved with a Windows byte order mark now load, and a config file the adapter can't parse is no longer overwritten.
- A dependency update fixes a high-severity denial-of-service bug in TOML config parsing.
Changed
- Project MCP server approvals are now shared across a repository's git worktrees. Approving a server in one checkout covers the same folder in the others, so a new worktree no longer asks again unless the server definition differs. This works for regular, bare, and
--separate-git-dirrepositories; only the main checkout of a--separate-git-dirrepository asks once on its own. Thanks to @MauricioRobayo for issue #708.
Fixed
- The project MCP server approval prompt now stays on screen until you answer it, including after
/reloadand panel saves. Before,/reloador another extension replacing the editor could hide it, leave MCP stuck starting, and make each prompt wait up to 30 seconds. Thanks to @Gybra for issue #690 and PR #691, and to @nazerim for issue #695. - Disabled project MCP servers no longer ask for approval or delay interactive startup. Thanks to @ismailokta for reporting issue #685.
- The approval prompt now labels its path as the project config that needs approval, instead of calling it the server's source. A project file that only enables a server you defined globally no longer looks like it defines the command. Thanks to @nazerim for reporting issue #695.
- When a server fails to connect, the agent now sees why.
mcp({})status, themcptool's "not available" replies, and direct tools show the connection error (for examplespawn demo ENOENT) next to "failed 12s ago", shortened to one line. Before, only/mcp-adapter statusand the panel showed it. - MCP config files saved with a UTF-8 byte order mark, as some Windows editors do, now load instead of failing to parse. This covers adapter, shared, and imported JSON configs and imported TOML configs, and
pi-mcp-adapter initkeeps the servers in such a file. Thanks to @quifox for PR #697. - Adding servers, imports, or direct tools no longer overwrites an existing MCP config file that fails to parse or has the wrong shape. The adapter reports the error and leaves the file alone; empty files can still be set up. Thanks to @quifox for PR #693.
- Repeating a word in an MCP tool search no longer hides tools that match it. Thanks to @kojizada490-wq for PR #678.
- Searching the
/mcp-adapterpanel by server name now finds disabled or unconnected servers, so you can select and enable them. Thanks to @nazerim for reporting issue #696. - When Jev semantic search times out, is rate limited, or is unavailable, the lexical fallback now returns only tools from
settings.jev.allowedServers, as the semantic results already did. Thanks to @quifox for PR #698. - Changing a stdio server's
inheritEnvorliteralEnvsetting now refreshes its cached tools, so search and direct tools no longer show stale entries. Thanks to @kojizada490-wq for PR #683.
Security
smol-tomlnow requires 1.9.0 or later, which fixes a high-severity denial of service on malformed TOML. The lockfile also moveshono, which comes in through the MCP SDK, to a release with its moderate advisories fixed, sonpm auditon a lockfile install reports no production vulnerabilities. Thanks to @jvpacini-CW for PR #694.