effectRequired
PermissionEffect
allow or deny when the rule applies.
toolsOptional
readonly string[] | undefined
Tool name patterns; * matches any characters. Omit to apply to every tool.
pathsOptional
readonly string[] | undefined
Repository path globs (**, * and ?) matched against the paths a call declares. An allow rule applies when every path matches, a deny rule when one does; a call that declares no paths never matches, nor does a path outside the repository.
commandsOptional
readonly string[] | undefined
Command patterns where * matches any characters, compared with the command a call declares; a call without a declared command never matches. Shell metacharacters can evade these patterns.
reasonOptional
string | undefined
Explanation returned to the model when this deny rule applies, default Denied by permission rule <n>.