Guard · Permissions

Permissions

Claude Code permission posture per tracked repo: the resolved defaultMode, the allow / ask / deny rules, configured hooks, and a 0 to 100 posture score that flags risky setups (bypassPermissions in repo settings, an overbroad Bash allow, no deny rules at all).

Start here if you want to see what is exposed in a repo and whether it is contained: Security.

See it in motion

Where to find it

  • Localhost: /permissions.html?repo=<id>
  • API: GET /api/permissions?repo=<id> (404 for an unknown repo)
  • Keyboard: ⌘ K then permissions
  • Navigation: Local settings in the sidebar, then Permissions under Workspace utilities. The page answers at its URL either way.

What it does for you

See, at a glance, whether each repo's permission posture is safe.The score starts at 100 and loses points per finding by severity. The findings: defaultMode set to bypassPermissions in project or local settings (no permission prompts at all), an allow rule of Bash, Bash(*) or * that removes the prompt for every matching tool, no permissions.deny rules (nothing blocks reads of secret files such as .env), and a defaultMode that is not a recognized Claude Code mode. Each finding names the fix.
Local settings override project settings, and both are read.defaultMode, the allow / ask / deny rules and the hooks are merged across the project settings and the local settings, with local winning on defaultMode. The same read lists the MCP servers configured for the repo and the autonomy zones the declared intent names; when either input is unavailable the page shows no finding for it rather than an empty-state claim.

Read more

Last updated