97a06261b63632da1fcf262e496ce57912871e7c
allowlist.json must be root-owned so POST /allowlist is the only write path; direct file edit bypasses audit log and danger veto. No cross- bridge sync — allowlists grow organically per server.
Description
Claude Code session context, playbooks, and automation specs
Languages
Markdown
100%