Hey, thanks for the detailed report and the repro script. Super helpful.
This is a known gap. MCP servers passed via session/new in ACP mode aren’t properly wired into the approval flow. You’re right that --approve-mcps only works for the interactive CLI flow, and --yolo doesn’t cover MCP approval.
The team is aware of this.
For now, the pre-approval workaround you found is the only option, unfortunately. I also saw your related report about permission rejection not being reported to the client, and I flagged that too.
I’ll update here if there’s any news on this.