Skip to content

Limit export MCP pre-approval to its five required read tools - #22

Open
manuelconcari-ai wants to merge 1 commit into
hackenproof-public:mainfrom
manuelconcari-ai:codex/export-mcp-read-allowlist
Open

manuelconcari-ai wants to merge 1 commit into
hackenproof-public:mainfrom
manuelconcari-ai:codex/export-mcp-read-allowlist

Conversation

@manuelconcari-ai

Copy link
Copy Markdown

The export prerequisite recommends a user-wide grant for every tool exposed by the HackenProof MCP server, although the published workflow requires only five reads. That grant can also match the repository's triage write tools.

Replace both wildcard recommendations with the five exact tool names, in optional project-local settings or in user settings for someone who wants one grant across projects. Explain how to remove an earlier broad grant from every settings file that supplies it: permission lists merge across files, so adding narrower entries does not revoke the wildcard. Preserve the export workflow and distinguish MCP approval from local file permissions and the triage skills' confirmation requirements.

Validation: checked the full export skill and Markdown template, including program discovery, pagination, comments and attachment handling. The patch changes only the prerequisite section of one file; the example JSON parses and contains exactly the five MCP reads required by that workflow. The patch applies to main at 60d8813.

This narrows a documented permission recommendation. No connected MCP server or Claude Code runtime was exercised, and no deployed permission bypass or runtime enforcement claim is made.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant