{
  "permissions": {
    "allow": [
      "Read(//home/zorz/sites/npm-tests/ccc-manual-test-v1/**)",
      "Bash(npx drupal-claude-collective:*)",
      "Read(//home/zorz/sites/npm-tests/ccc-testing-v2/**)",
      "Bash(npm install:*)",
      "Bash(npm run test:jest:*)",
      "Bash(npm test)",
      "WebSearch",
      "WebFetch(domain:context7.com)",
      "Bash(git add:*)",
      "Bash(git commit:*)",
      "Bash(npm version:*)",
      "Bash(git push:*)",
      "Bash(cat:*)",
      "Bash(npm publish)",
      "Bash(npm view:*)",
      "Bash(npx jest:*)",
      "Bash(npm test:*)",
      "Bash(mkdir:*)",
      "WebFetch(domain:raw.githubusercontent.com)",
      "Bash(git checkout:*)",
      "WebFetch(domain:github.com)",
      "Bash(wc:*)",
      "Bash(task-master parse-prd:*)",
      "mcp__task-master__parse_prd",
      "mcp__task-master__get_tasks",
      "mcp__task-master__get_task",
      "WebFetch(domain:registry.npmjs.org)",
      "Bash(npx -y task-master-ai update-task --id=1 --prompt=\"Add to this task: INDEX.md must include a Behavioral Rules section \\(~15-20 lines\\) incorporating 6 high-impact CLAUDE.md additions identified by the Claude Code Insights usage report \\(addresses #1 friction: 26 buggy code events\\). Rules: 1\\) After multi-file changes, grep codebase for remaining references to modified functions/constants/variables. 2\\) After Drupal service/Twig changes, verify service injections, DB table/column names, and Twig filter existence. 3\\) Use system-configured values not magic numbers. 4\\) When removing something, remove from ALL locations and grep to confirm. 5\\) Write output to project directory not inline. 6\\) CSS: target specific elements within context. Adjust INDEX.md budget to ~95 lines. Update test strategy accordingly.\" --projectRoot=/home/zorz/sites/drupal-claude-code-sub-agent-collective)",
      "mcp__task-master__set_task_status",
      "Bash(git -C /home/zorz/sites/drupal-claude-code-sub-agent-collective add:*)"
    ],
    "deny": [],
    "ask": []
  },
  "sandbox": {
    "enabled": true,
    "autoAllowBashIfSandboxed": true
  }
}
