Skip to content

chore(claude): stop auto-enabling project MCP servers and drop Playwright MCP - #729

Open
neelay-aign wants to merge 2 commits into
mainfrom
chore/mcp-server-allowlist
Open

neelay-aign wants to merge 2 commits into
mainfrom
chore/mcp-server-allowlist

Conversation

@neelay-aign

@neelay-aign neelay-aign commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Removes enableAllProjectMcpServers: true from .claude/settings.json. With it set, every server in .mcp.json started on developer machines without a prompt, including any server added later by a PR. Without it, Claude Code asks each developer before starting a project server.
  • Deletes .mcp.json. Its only entry was the Playwright MCP server added in chore: add Playwright MCP server config to .mcp.json [PYSDK-117] #608. Nothing in the repo uses that server (no tests, skills, docs or CI), and it ran @playwright/mcp@latest, so each start pulled whatever version was newest on npm.
  • Adds .mcp.json back to .gitignore, as it was before chore: add Playwright MCP server config to .mcp.json [PYSDK-117] #608. A shared project MCP server now has to be added deliberately.
  • Prompted by an external hardening report. They described it as a hardening point, not an incident.

To keep using Playwright MCP, add it at user scope:

claude mcp add --scope user playwright -- npx @playwright/mcp@latest

Follow-up (not in this PR)

  • Developers should check their own ~/.claude/settings.json and .claude/settings.local.json for enableAllProjectMcpServers, because a repo review can't see those files.

Test plan

  • .claude/settings.json is still valid JSON
  • Start Claude Code in the repo and confirm /mcp lists no project-scoped servers

🤖 Generated with Claude Code

… all

Replaces enableAllProjectMcpServers with an explicit enabledMcpjsonServers
list so a server added to .mcp.json later requires each developer's
approval before it starts.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@neelay-aign neelay-aign added skip:test:long_running Skip long-running tests (≥5min) type:chore Tooling, maintenance, routine task (conventional chore) security Addresses a security advisory, CVE, or hardens security posture labels Oct 1, 2026
@neelay-aign
neelay-aign requested a review from a team as a code owner October 1, 2026 15:01
@neelay-aign neelay-aign added skip:test:long_running Skip long-running tests (≥5min) type:chore Tooling, maintenance, routine task (conventional chore) security Addresses a security advisory, CVE, or hardens security posture labels Oct 1, 2026
@neelay-aign neelay-aign self-assigned this Oct 1, 2026
Nothing in the repo uses it; developers who want it can add it at user
scope. Ignoring .mcp.json keeps project MCP servers out of the repo.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@neelay-aign neelay-aign changed the title chore(claude): allowlist project MCP servers instead of auto-enabling all chore(claude): stop auto-enabling project MCP servers and drop Playwright MCP Oct 1, 2026
@codecov

codecov Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

❗ There is a different number of reports uploaded between BASE (4bc4304) and HEAD (cda2c09). Click for more details.

HEAD has 4 uploads less than BASE
Flag BASE (4bc4304) HEAD (cda2c09)
5 1

see 24 files with indirect coverage changes

@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Addresses a security advisory, CVE, or hardens security posture skip:test:long_running Skip long-running tests (≥5min) type:chore Tooling, maintenance, routine task (conventional chore)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant