Apply recommended fixes
apply_fixesApplies MCP security fixes to project files: adds permission rules, pins package versions, replaces secrets with references. Preview changes before writing.
Instructions
Fixes findings in the project's own files. permissions: adds the recommended permissions.ask rules for tools that execute code, delete data or write files to .claude/settings.json (needs confirm_launch, because the servers are listed to classify their tools). pin-versions: pins unpinned npx/uvx packages in .mcp.json to the registry's current version (needs confirm_network). env-refs: replaces literal secrets in .mcp.json env/headers with ${VAR} references. Without write=true it only shows the planned edits. Every written file is backed up under ~/.claude/mcp-security/backups/ first; ~/.claude.json is never modified.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| fixes | Yes | ||
| write | No | false = dry run. Show the plan to the user first, then call again with write=true after they agree. | |
| servers | No | Servers considered for the permissions fix. | |
| project_dir | No | ||
| confirm_launch | No | ||
| confirm_network | No |