Skip to content

settings-permission-invalid-rule ​

Permission rules must use valid Tool(pattern) syntax

Error

Rule Details ​

This rule checks the syntax of permission rule strings in settings.json and settings.local.json. Each rule must be either a plain tool name like "Bash" or a tool name with a pattern like "Bash(npm run *)". It checks the outer delimiter, empty rule strings, and MCP specifiers ignored in settings. Parentheses inside a specifier are literal. Incorrect syntax prevents the permission system from matching commands properly, which can lead to unexpected access behavior.

Incorrect ​

Permission rule with unmatched parentheses

json
{
  "permissions": {
    "allow": ["Bash(npm run build"]
  }
}

Empty permission rule string

json
{
  "permissions": {
    "deny": [""]
  }
}

Correct ​

Valid permission rules with proper syntax

json
{
  "permissions": {
    "allow": ["Bash(npm run *)", "Read", "WebFetch(domain:example.com)"]
  }
}

How To Fix ​

Ensure each permission rule uses the format "Tool" or "Tool(pattern)". Check for outer parentheses and non-empty values. Remove any trailing or leading whitespace.

Options ​

This rule does not have any configuration options.

Resources ​

Version ​

Available since: v0.2.0