MCPs โบ Dev tools โบ What's Allowed
What your coding agent can do without asking you. Reads every settings file that contributes permission rules โ managed policy, project, local, user โ and reports the merged picture: which file each rule came from, which defaultMode wins, what proceeds unattended, and which rules the client accepts and then ignores (path rules on Write/Glob, unanchored allow globs, /path rules in user settings that anchor at the config directory, allow rules a deny rule reaches first). Four read-only tools: whats_allowed (full summary), permission_sources, rule_findings, unattended_surface. Read-only by construction โ no child processes, no network, no writes; values of env entries are never read, only their names. MIT licensed. Free and MIT, with no telemetry and nothing held back. Built by Shift The Culture, who also publish paid kits for the failure modes this server surfaces: https://shifttheculture.media/agent-tools
Not monetized yet
Turn What's Allowedโs tool calls into revenue: one disclosed sponsored slot, 70% revenue share, fail-open by design.
Install What's Allowed
For anyone using What's Allowed โ no Lulu account needednpx -y @smithery/cli@latest install shift-the-culture/whats-allowed-mcp --client claude
Real-time weather for any city, built on the lulu-ads widget gallery. First-party, free forever.
View server โFAQ
What's Allowed installs from source โ follow the repository README.
Unrated out of 100, computed from cross-registry traction signals (installs, stars, registry presence) โ never influenced by sponsorship.
Works well together