What your coding agent can do without asking you. Reads every settings file that contributes permission rules — managed…
What your coding agent can do without asking you. Reads every settings file that contributes permission rules — managed policy, project, local, user — and reports the merged picture: which file each rule came from, which defaultMode wins, what proceeds unattended, and which rules the client accepts and then ignores (path rules on Write/Glob, unanchored allow globs, /path rules in user settings that anchor at the config directory, allow rules a deny rule reaches first). Four read-only tools: whats_allowed (full summary), permission_sources, rule_findings, unattended_surface. Read-only by construction — no child processes, no network, no writes; values of env entries are never read, only their names. MIT licensed. Free and MIT, with no telemetry and nothing held back. Built by Shift The Culture, who also publish paid kits for the failure modes this server surfaces: https://shifttheculture.media/agent-tools
shift-the-culture
mcp
free
Others in the same category, ranked by how often they are opened.