Appearance
SEC622 / MCP-AUTOAPPROVE-GREP
SEC622 flags MCP configuration when autoApprove includes the exact bare tool token Grep.
Why It Matters
Bare Grep auto-approval grants unreviewed broad content-search authority without narrowing queries to reviewed scopes.
Trigger Shape
This rule matches parsed McpConfig content where autoApprove contains the exact string Grep.
How To Fix
Replace bare Grep auto-approval with narrower reviewed scopes such as Grep(todo:) or remove shared auto-approval for unrestricted content search.