claude-mcp-allow
Least-privilege Claude Code permission rules for MCP tools, generated from their annotations.
What it is
Generate permissions.allow and permissions.ask rules for every MCP tool Claude Code can reach, from the annotations each server reports on tools/list: a tool that says readOnlyHint: true (and not destructiveHint: true) gets an allow rule, everything else gets an ask rule, one exact mcp__<server>__<tool> rule per tool and never a glob. --write merges the rules into the settings file you choose, --diff shows what would change, and --check reconnects later and exits 1 when a server's annotations have drifted from the rules you saved.
Install
npx @basitalisandhu/claude-mcp-allow # run without installing
npm install -g @basitalisandhu/claude-mcp-allow@0.1.1 # or install the claude-mcp-allow command
From the README; see the full README for every option.
Links
Releases
Topics: agent-security, ai-agents, ai-security, claude-code, cli, developer-tools, devsecops, drift-detection, hacktoberfest, least-privilege, llm-security, mcp, mcp-client, model-context-protocol, permissions, security-tools, tool-annotations, typescript