Skip to content

feat(claude): confine read-only runs to Read, Glob and Grep - #41

Merged
oritwoen merged 1 commit into
mainfrom
feat/claude-read-only-tools
Sep 13, 2026
Merged

oritwoen merged 1 commit into
mainfrom
feat/claude-read-only-tools

Conversation

@aeitwoen

Copy link
Copy Markdown
Contributor

Claude Code gets a read-only mode: --tools Read,Glob,Grep with --strict-mcp-config, three inspection tools and zero MCP servers. Rejecting readOnly: true on the harness most people have installed was hard to defend. Checked on 2.1.175 and 2.1.268 with a prompt ordered to write through Write, Bash, ToolSearch and an MCP tool: every call refused, the control run wrote. Plan mode lost the audition, its classifier waved a shell redirect through.

@aeitwoen
aeitwoen requested a review from oritwoen as a code owner September 13, 2026 19:25
@aeitwoen aeitwoen self-assigned this Sep 13, 2026
@coldtea-pr-lens

coldtea-pr-lens Bot commented Sep 13, 2026

Copy link
Copy Markdown

◈ PR Lens

🟢 +0 new · 🟠 ~1 changed · 🔴 -0 removed · 1 flow · 1 file · commit 28e72d4


Architecture

Architecture diagram for agntn/harnesses at 28e72d4

1 component touched across 2 lanes.

Open the interactive canvas


Data flow

Data flow diagram for agntn/harnesses at 28e72d4

Building read-only Claude invocation

Open the interactive canvas


View

  • Architecture lens
  • Data flow lens
  • Expand every detail

Tip

Open a diagram on the canvas, then press W or click play to walk through the change one step at a time.

🪧 More tips
  • Run npx skills add coldteadotai/pr-lens, then tell your coding agent: "Diagram the change you just made with PR Lens and attach it to the pull request."
  • Run npx @coldtea/pr-lens-cli analyze --base origin/main on a branch, then npx @coldtea/pr-lens-cli render .pr-lens/graph.json. Same lenses, your own model key, before the pull request exists.
  • Untick Architecture lens or Data flow lens under View to hide a diagram, or tick Expand every detail to open every section. The comment redraws in a few seconds.
  • Click the link under each diagram to open it on a canvas you can zoom, pan and step through.
  • The diagrams are links. Click one to open it on the canvas, then press W or click play to walk through the change.
  • The CLI's render reads .github/pr-lens.yml and applies your renames, exclusions and lane pins at draw time.
  • Set github.comment.collapsed: true in .github/pr-lens.yml to fold the comment behind one View architecture and data flow row. Drawing still runs on every push.
  • Add .github/workflows/pr-lens.yml with coldteadotai/pr-lens/packages/action@v0 and your model provider's key as its api-key to run PR Lens from your own CI. Any /chat/completions endpoint works.
  • Push a commit and the comment redraws for the new head. A slow older run never overwrites a newer one.
  • Switch GitHub to dark mode and the diagrams follow. The moving dots are this pull request's data in motion.

Thanks for using PR Lens! It's built by Coldtea, free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

@oritwoen
oritwoen merged commit c980d48 into main Sep 13, 2026
6 checks passed
@oritwoen
oritwoen deleted the feat/claude-read-only-tools branch September 13, 2026 19:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants