Home / MCP tooling

claude-mcp-allow

Least-privilege Claude Code permission rules for MCP tools, generated from their annotations.

TypeScript · MIT · latest v0.1.0

What it is

Generate permissions.allow and permissions.ask rules for every MCP tool Claude Code can reach, from the annotations each server reports on tools/list: a tool that says readOnlyHint: true (and not destructiveHint: true) gets an allow rule, everything else gets an ask rule, one exact mcp__<server>__<tool> rule per tool and never a glob. --write merges the rules into the settings file you choose, --diff shows what would change, and --check reconnects later and exits 1 when a server's annotations have drifted from the rules you saved.

Install

npx @basitalisandhu/claude-mcp-allow                    # run without installing
npm install -g @basitalisandhu/claude-mcp-allow@0.1.1   # or install the claude-mcp-allow command

From the README; see the full README for every option.

Releases

Topics: agent-security, ai-agents, ai-security, claude-code, cli, developer-tools, devsecops, drift-detection, hacktoberfest, least-privilege, llm-security, mcp, mcp-client, model-context-protocol, permissions, security-tools, tool-annotations, typescript