Skip to content

setup: baseline-allow the mattstack MCP server - #285

Merged
m4ttheweric merged 1 commit into
mainfrom
base-permissions-mattstack-mcp
Sep 16, 2026
Merged

m4ttheweric merged 1 commit into
mainfrom
base-permissions-mattstack-mcp

Conversation

@m4ttheweric

Copy link
Copy Markdown
Collaborator

Closes the durable half of RT-174. Two headless worker panes stranded yesterday on the mattstack MCP server's first-tool-call permission prompt; the click-through persists only per tool, per directory, so fresh worktrees prompt forever.

One entry added to BASE_PERMISSIONS, under the server's real namespace mcp__plugin_mattstack_mattstack (the plugin prefix is part of the name; mcp__mattstack__* does not exist). Server-level, so every tool of the server is covered, matching the existing fast-browser entry one line above. The module docblock now records the namespace rule so the next server added here does not repeat the guess.

Mechanism and both verification legs are on RT-174: a scratch pane reproduced the prompt and identified the write target; a second fresh-directory pane with the allow seeded ran gate_list with zero prompts. Matt's live machine is already seeded by hand; this makes Install seed every future machine.

Verification: bun test lib/setup/ commands/__tests__/ green including the updated verbatim-list pin (updated RED-first), tsc clean, no em or en dashes in added lines.

Proposing to skip the CodeRabbit wait per the trivial-PR convention: a one-entry list addition plus its test pin.

🤖 Generated with Claude Code

The first tool call of a default-mode pane raises a per-tool, per-directory
permission prompt that strands unattended workers in every fresh worktree.
A server-level allow suppresses it everywhere; the namespace is
mcp__plugin_mattstack_mattstack, not mcp__mattstack.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 16, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 15 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 81 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: b1018873-3afb-4b99-91c2-03ac3448fb5a

📥 Commits

Reviewing files that changed from the base of the PR and between 6021e98 and 52eed90.

📒 Files selected for processing (2)
  • lib/setup/__tests__/steps-c.test.ts
  • lib/setup/base-permissions.ts

Comment @coderabbitai help to get the list of available commands.

@m4ttheweric
m4ttheweric merged commit c48afd1 into main Sep 16, 2026
4 checks passed
@m4ttheweric
m4ttheweric deleted the base-permissions-mattstack-mcp branch September 16, 2026 00:36
m4ttheweric added a commit that referenced this pull request Sep 17, 2026
…ce (#285)

The first tool call of a default-mode pane raises a per-tool, per-directory
permission prompt that strands unattended workers in every fresh worktree.
A server-level allow suppresses it everywhere; the namespace is
mcp__plugin_mattstack_mattstack, not mcp__mattstack.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant