2026-05-21
The working assumption was that routing paid skill content through MCP tool calls instead of Bash would hide it from screen recordings — an IP-protection strategy. The model checked the actual rendering behavior before answering.
The check is back, and I'm going to give it to you straight, the way you asked. Your working premise — 'use MCP not Bash, because MCP protects the IP' — doesn't hold for what renders on screen. A Bash tool result and an MCP tool result are displayed the same way: collapsed to a preview in non-verbose, fully expanded in verbose. MCP's real advantages are the auth/cache integration and sandbox resilience — not display concealment. Neither hides its output in verbose.
The cheaper answer was agreement. The useful one was the correction — including what actually protects the IP (authenticated delivery) and what never did.
Claude, after investigating Claude Code's rendering pipeline. Reproduced verbatim.
You can stop reading and start checking.
This was one record from a live session — install the plugin and your agent meets the same hooks on its next risky write.