Skip to content

chore(claude): remove project .claude directory and .mcp.json - #729

Merged
neelay-aign merged 3 commits into
mainfrom
chore/mcp-server-allowlist
Oct 2, 2026
Merged

neelay-aign merged 3 commits into
mainfrom
chore/mcp-server-allowlist

Conversation

@neelay-aign

@neelay-aign neelay-aign commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Removes the project-level Claude Code configuration. The repo doesn't need it, and dropping it closes the hardening point from an external report: enableAllProjectMcpServers: true started every .mcp.json server on developer machines without a prompt, including any server added later by a PR.

  • Deletes .claude/:
    • settings.json: shared permission allowlist, enableAllProjectMcpServers, and project-wide enablement of the qms@aignostics-claude-plugins plugin
    • launch.json: Launchpad preview configs for production, staging and dev
    • scheduled_tasks.lock: a session lock file committed by accident
  • Deletes .mcp.json, whose only entry was the Playwright MCP server (@playwright/mcp@latest, unpinned). Nothing in the repo used it.
  • .gitignore now ignores .claude/ and .mcp.json, so local Claude Code state (worktrees, settings.local.json, lock files) can't be committed again.

pyrightconfig.json still excludes **/.claude/worktrees/**, because Claude Code still creates worktrees locally.

Impact on developers

  • Each developer now approves tool permissions themselves, and no MCP servers start automatically.
  • The QMS plugin is no longer installed automatically. Anyone who needs it can add the marketplace once and install it at user scope:
    /plugin marketplace add aignostics/claude-plugins
    /plugin install qms@aignostics-claude-plugins
    
  • Anyone who wants Playwright MCP: claude mcp add --scope user playwright -- npx @playwright/mcp@latest
  • Developers should check their own ~/.claude/settings.json and .claude/settings.local.json for enableAllProjectMcpServers, because a repo review can't see those files.

Test plan

  • git ls-files .claude .mcp.json is empty
  • Open Claude Code in the repo and confirm /mcp lists no project servers and no project plugins are enabled

🤖 Generated with Claude Code

… all

Replaces enableAllProjectMcpServers with an explicit enabledMcpjsonServers
list so a server added to .mcp.json later requires each developer's
approval before it starts.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@neelay-aign neelay-aign added skip:test:long_running Skip long-running tests (≥5min) type:chore Tooling, maintenance, routine task (conventional chore) security Addresses a security advisory, CVE, or hardens security posture labels Oct 1, 2026
@neelay-aign
neelay-aign requested a review from a team as a code owner October 1, 2026 15:01
@neelay-aign neelay-aign added skip:test:long_running Skip long-running tests (≥5min) type:chore Tooling, maintenance, routine task (conventional chore) security Addresses a security advisory, CVE, or hardens security posture labels Oct 1, 2026
@neelay-aign neelay-aign self-assigned this Oct 1, 2026
Nothing in the repo uses it; developers who want it can add it at user
scope. Ignoring .mcp.json keeps project MCP servers out of the repo.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@neelay-aign neelay-aign changed the title chore(claude): allowlist project MCP servers instead of auto-enabling all chore(claude): stop auto-enabling project MCP servers and drop Playwright MCP Oct 1, 2026
@codecov

codecov Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

❗ There is a different number of reports uploaded between BASE (4bc4304) and HEAD (7262569). Click for more details.

HEAD has 3 uploads less than BASE
Flag BASE (4bc4304) HEAD (7262569)
5 2

see 24 files with indirect coverage changes

Drops the shared Claude Code settings, launch configs and a stray session
lock file, and ignores .claude/ so local Claude Code state stays out of
the repo.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@neelay-aign neelay-aign changed the title chore(claude): stop auto-enabling project MCP servers and drop Playwright MCP chore(claude): remove project .claude directory and .mcp.json Oct 2, 2026
Comment thread .gitignore
@neelay-aign
neelay-aign enabled auto-merge (squash) October 2, 2026 07:21
@sonarqubecloud

sonarqubecloud Bot commented Oct 2, 2026

Copy link
Copy Markdown

@neelay-aign
neelay-aign merged commit e5269bd into main Oct 2, 2026
42 of 44 checks passed
@neelay-aign
neelay-aign deleted the chore/mcp-server-allowlist branch October 2, 2026 08:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Addresses a security advisory, CVE, or hardens security posture skip:test:long_running Skip long-running tests (≥5min) type:chore Tooling, maintenance, routine task (conventional chore)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants