Generate an approved-server policy
generate_policyCreate a .mcp-security.json policy that approves current MCP servers with pinned versions and flags later additions as shadow servers. Read-only; commit it to enforce CI and audit checks.
Instructions
Returns a .mcp-security.json policy that approves exactly the MCP servers configured now (and their remote hosts) and requires pinned versions. Commit it to the repository so CI, session checks and audits flag any server added later that is not on the list (shadow MCP servers). Read-only: returns the JSON, does not write it.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| project_dir | No |