build: reordered agent perms
CI / benchmark-publish (push) Waiting to run
CI / push-validation (push) Successful in 30s
CI / helm (push) Successful in 42s
CI / build (push) Successful in 47s
CI / quality (push) Successful in 1m14s
CI / lint (push) Successful in 1m25s
CI / typecheck (push) Successful in 1m35s
CI / security (push) Successful in 1m34s
CI / e2e_tests (push) Successful in 5m57s
CI / integration_tests (push) Successful in 7m11s
CI / unit_tests (push) Successful in 9m0s
CI / docker (push) Failing after 1s
CI / coverage (push) Successful in 12m23s
CI / status-check (push) Failing after 3s

This commit is contained in:
2026-05-02 14:33:45 -04:00
parent 6ee703fef5
commit ce396d2b43
34 changed files with 170 additions and 170 deletions
+5 -5
View File
@@ -21,16 +21,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": allow
+5 -5
View File
@@ -21,16 +21,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": allow
+5 -5
View File
@@ -23,16 +23,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": allow
+5 -5
View File
@@ -14,16 +14,16 @@ permission:
"doom_loop": deny
"question": deny
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
"sequential-thinking*": deny
"context7*": deny
+5 -5
View File
@@ -17,16 +17,16 @@ permission:
"doom_loop": deny
"question": deny
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
"sequential-thinking*": deny
"context7*": deny
+5 -5
View File
@@ -16,16 +16,16 @@ permission:
"doom_loop": deny
"question": deny
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
"sequential-thinking*": deny
"context7*": deny
+5 -5
View File
@@ -19,16 +19,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": allow
+5 -5
View File
@@ -17,16 +17,16 @@ permission:
"doom_loop": deny
"question": deny
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
"sequential-thinking*": deny
"context7*": deny
+5 -5
View File
@@ -14,16 +14,16 @@ permission:
"doom_loop": deny
"question": deny
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
"sequential-thinking*": deny
"context7*": deny
@@ -16,16 +16,16 @@ permission:
"doom_loop": deny
"question": deny
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
"sequential-thinking*": deny
"context7*": deny
+5 -5
View File
@@ -20,16 +20,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": deny
+5 -5
View File
@@ -15,16 +15,16 @@ permission:
"doom_loop": deny
"question": deny
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
"sequential-thinking*": deny
"context7*": deny
+5 -5
View File
@@ -16,16 +16,16 @@ permission:
"doom_loop": deny
"question": deny
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
"sequential-thinking*": deny
"context7*": deny
+5 -5
View File
@@ -23,16 +23,16 @@ permission:
read: allow
grep: allow
glob: allow
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": allow
+5 -5
View File
@@ -15,16 +15,16 @@ permission:
"doom_loop": deny
"question": deny
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
"sequential-thinking*": deny
"context7*": deny
@@ -26,16 +26,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": deny
+5 -5
View File
@@ -19,16 +19,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": deny
+5 -5
View File
@@ -19,16 +19,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": allow
+5 -5
View File
@@ -22,16 +22,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": deny
+5 -5
View File
@@ -23,16 +23,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": allow
+5 -5
View File
@@ -18,16 +18,16 @@ permission:
"doom_loop": deny
"question": deny
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
"sequential-thinking*": allow
"context7*": deny
@@ -18,16 +18,16 @@ permission:
"doom_loop": deny
"question": deny
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
"sequential-thinking*": allow
"context7*": deny
+5 -5
View File
@@ -18,16 +18,16 @@ permission:
"doom_loop": deny
"question": deny
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
"sequential-thinking*": allow
"context7*": deny
+5 -5
View File
@@ -18,16 +18,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": allow
+5 -5
View File
@@ -25,16 +25,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": allow
+5 -5
View File
@@ -22,16 +22,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": deny
+5 -5
View File
@@ -21,16 +21,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": deny
+5 -5
View File
@@ -21,16 +21,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": deny
+5 -5
View File
@@ -21,16 +21,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": deny
+5 -5
View File
@@ -21,16 +21,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": deny
+5 -5
View File
@@ -22,16 +22,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": deny
+5 -5
View File
@@ -21,16 +21,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": deny
+5 -5
View File
@@ -21,16 +21,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# I don't think MCP permissions work, but just in case they do these two should be the only ones usually allowed
"sequential-thinking*": deny
+5 -5
View File
@@ -20,16 +20,16 @@ permission:
"question": deny
# All agents are supposed to be working in isolated repos in `/tmp`, so this forces that
read:
"*": allow
write:
"*": deny
external_directory:
"/tmp/*": allow
edit:
"*": deny
"/tmp/*": allow
external_directory:
write:
"*": deny
"/tmp/*": allow
read:
"*": allow
# MCP permissions
"sequential-thinking*": allow