permissions= and the agent’s built-in filesystem tools respect them.
Permissions only apply to the built-in filesystem tools (ls, read_file, glob, grep, write_file, edit_file). Custom tools and MCP tools that access the filesystem are not covered. Permissions also do not apply to sandbox backends, which support arbitrary command execution via the execute tool.
Basic usage
Rule structure
Examples
Subagent permissions
Composite backends
Connect these docs to Claude, VSCode, and more via MCP for real-time answers.

