# How to Scope Analysis to a Specific Subdirectory in Monorepos

> Scope monorepo analysis to specific subdirectories using glob patterns instead of absolute paths to avoid security restrictions and analyze your code efficiently.

- Repository: [Yuxiang Lin/Understand-Anything](https://github.com/Lum1104/Understand-Anything)
- Tags: how-to-guide
- Published: 2026-06-02

---

**To scope analysis to specific subdirectories in monorepos, use glob patterns like `**/package.json` instead of absolute paths, as security rules in Understand-Anything deny direct reads to paths containing protected directories like `/cache/` or `/__modal/`.**

When working with the **Lum1104/Understand-Anything** repository to analyze complex monorepo structures, you must configure path resolution strategies that navigate security restrictions while targeting specific packages. The tool's security model denies direct file system access to absolute paths containing system directories, requiring alternative approaches to scope your analysis effectively.

## Understanding Absolute Path Restrictions

The Understand-Anything engine implements strict read rules that block access to absolute paths containing protected system locations. According to the source analysis, attempts to read files using absolute paths like [`/__modal/.../Understand-Anything/main/package.json`](https://github.com/Lum1104/Understand-Anything/blob/main//__modal/.../Understand-Anything/main/package.json) fail because the allow rules specifically restrict access patterns associated with `/cache/` directories and other sensitive system paths.

These restrictions prevent analysis tools from accessing temporary files or system-level directories, but they also block legitimate reads to monorepo files when using absolute path resolution.

## Using Glob Patterns for Subdirectory Scoping

To scope analysis to specific subdirectories without triggering security denials, configure the tool to use **glob patterns** that traverse relative paths rather than absolute file system locations.

### Targeting Configuration Files

Instead of specifying absolute paths, use recursive glob patterns to discover package configurations within your target subdirectory:

```javascript
// Analysis configuration for monorepo subdirectory scoping
const analysisConfig = {
  entryPoints: [
    "**/package.json"  // Discovers package.json in any subdirectory
  ],
  scope: [
    "packages/frontend/**",  // Limit to specific monorepo package
    "!**/node_modules/**"    // Exclude dependencies
  ]
};

```

### Filtering by Path Patterns

For precise control over which monorepo packages to analyze, combine directory prefixes with glob wildcards:

```json
{
  "include": [
    "apps/web/**/*.ts",
    "apps/web/**/*.tsx",
    "packages/shared/**/*.js"
  ],
  "exclude": [
    "**/*.test.ts",
    "**/dist/**"
  ]
}

```

This approach scopes the analysis to the `apps/web` and `packages/shared` subdirectories without requiring absolute path resolution that would trigger the `/cache/` and `/__modal/` security restrictions.

## Configuring Allow Rules for Monorepo Access

Update your analysis configuration to explicitly permit reads from your monorepo source directories while maintaining protections on system paths:

```yaml

# .understand-anything/config.yaml

permissions:
  allow:
    - "packages/**"
    - "apps/**"
    - "tools/**"
  deny:
    - "**/cache/**"
    - "**/__modal/**"
    - "**/node_modules/**"

```

## Summary

- **Absolute paths fail**: Direct reads to paths like [`/__modal/.../Understand-Anything/main/package.json`](https://github.com/Lum1104/Understand-Anything/blob/main//__modal/.../Understand-Anything/main/package.json) trigger security denials due to restrictions on `/cache/` and system directories.
- **Glob patterns succeed**: Use `**/package.json` and path-specific globs like `packages/frontend/**` to scope analysis without absolute path resolution.
- **Configure allow rules**: Explicitly permit your monorepo source directories in the tool configuration to enable subdirectory analysis while maintaining security boundaries.

## Frequently Asked Questions

### Why does Understand-Anything deny reads to absolute paths in monorepos?

Understand-Anything denies reads to absolute paths containing directories like `/__modal/` or `/cache/` to prevent unauthorized access to temporary system files and sensitive locations. As implemented in the Lum1104/Understand-Anything source, the security rules evaluate path patterns before allowing file system access, blocking attempts to read [`/__modal/.../Understand-Anything/main/package.json`](https://github.com/Lum1104/Understand-Anything/blob/main//__modal/.../Understand-Anything/main/package.json) even when targeting legitimate monorepo files.

### How do I analyze only one package in a large monorepo?

To analyze a single package, configure your scope using directory-specific glob patterns such as `packages/my-package/**` combined with `**/package.json` for dependency discovery. This approach restricts the analysis engine to traverse only the specified subdirectory structure without attempting to resolve absolute paths that would trigger security restrictions on system directories.

### Can I use multiple glob patterns to scope analysis across specific subdirectories?

Yes, you can define an array of glob patterns in your configuration to include multiple specific subdirectories while excluding others. For example, combining `apps/frontend/**`, `apps/api/**`, and `packages/shared/**` with exclusion patterns like `!**/node_modules/**` allows precise scoping across selected monorepo packages without processing unrelated directories or triggering absolute path security blocks.