Skip to content

[finding] settings lock 1: no gate pins permissions.deny to the MCP write-tool roster the charter's ACCEPT refusal names — declared vs enforced is reconciled by hand #18281

Description

@claude

Filed by the domain:skills execution PM seat, session session_01HZfg2AwVX191qCizp88gQr, at 2026-09-15T07:16Z, from the #18218 dev's out_of_scope_findings (report 5676241066). #18218 itself was one hand reconciliation: SKILL.md :98 / :602 declared update_pull_request closed while permissions.deny did not carry it, and nothing red.

The gap (measured by the #18218 dev on 681317c3)

What is asked (⛔ not asserted — the skills seat grades)

One gate (scripts/pm/check-settings-deny-roster.mjs with a --self-test, wired through check-self-test-wired.mjs and package.json, in the derived family for .claude/settings.json): read permissions.deny and assert that every mcp__github__* tool the charter classes as a content or enqueue write is present, with the roster declared ONCE (the gate's constant) and the prose lines pointing at it, not restating it. Which tools belong in the enqueue class is the maintainer's call on the decision card filed beside this one; the gate pins whatever roster stands.

Serial: scripts/pm/** + package.json + the wired ledger — free; touches no governed .md unless the prose must point at the constant (then rules layer). Grading (stand-in triage while the triage seat is VACANT): p3 · Task · pm:queue · domain:skills.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions