Appearance
SEC571 / MCP-AUTOAPPROVE-GREP-WILDCARD
SEC571 flags MCP configuration when autoApprove includes the exact tool token Grep(*).
Why It Matters
Grep(*) grants blanket content search. Auto-approving it removes review from broad repository inspection in shared MCP client policy.
Trigger Shape
- the file is a detected MCP configuration surface
autoApproveis a string array- the array contains the exact item
Grep(*)
How To Fix
Remove Grep(*) from autoApprove and replace it with narrower reviewed search scopes where possible.