Understanding Permission Settings for Claude Code in ai-job-search

The ai-job-search repository defines Claude Code's permission settings in .claude/settings.json, explicitly whitelisting only specific skills and bash commands while denying all other actions by default.

The ai-job-search project implements a restrictive, security-first permission model for Claude Code that limits the AI assistant to predefined, job-application-specific operations. By configuring these permission settings in a centralized JSON file, the repository ensures secure, reproducible automation while preventing unintended system access.

Where Permission Settings for Claude Code Are Defined

All permission configuration for Claude Code lives in the repository-scoped file .claude/settings.json. As noted in the project setup documentation, shared Claude Code permissions now live in this specific location rather than in local override files【SETUP.md†L340-L344】.

The repository structure visually identifies this file in the project tree as settings.json # Claude Code permissions (shared, scoped)【README.md†L195-L196】. These settings apply to all Claude Code commands run from the repository root, ensuring consistent behavior across different development environments.

If a previous version of the repository contained .claude/settings.local.json, it should be removed or carefully reviewed, as local settings merge on top of the shared baseline and can unintentionally broaden the allowed command surface.

Allowed Permission Types

The permission model uses a default-deny approach. Only commands explicitly listed in the allow array within the permissions object are granted to Claude Code.

Skill Permissions

The repository grants access to one specific skill:

  • Skill(job-application-assistant) – grants Claude Code access to the built-in "job-application-assistant" skill set, enabling specialized capabilities for processing job applications.

Bash Command Permissions

The configuration permits execution of specific bash command patterns using wildcard syntax:

  • Bash(bun run:*) – any command starting with bun run
  • Bash(python salary_lookup.py:*) – any invocation of python salary_lookup.py with arguments
  • Bash(python3 salary_lookup.py:*) – any invocation using python3 for the salary lookup script
  • Bash(python tools/verify_pdf.py:*) – any python execution of the PDF verification tool
  • Bash(python3 tools/verify_pdf.py:*) – any python3 execution of the PDF verification tool
  • Bash(pdftotext:*) – any use of the pdftotext binary for text extraction

All other bash commands remain blocked unless explicitly added to the allow array.

Inspecting Current Permissions

To verify which permission settings for Claude Code are currently active in your session, inspect the central configuration file:


# Inside the repository root

claude run "cat .claude/settings.json"

The output follows this structure:

{
  "permissions": {
    "allow": [
      "Skill(job-application-assistant)",
      "Bash(bun run:*)",
      "Bash(python salary_lookup.py:*)",
      "Bash(python3 salary_lookup.py:*)",
      "Bash(python tools/verify_pdf.py:*)",
      "Bash(python3 tools/verify_pdf.py:*)",
      "Bash(pdftotext:*)"
    ]
  }
}

Modifying Permission Settings for Claude Code

Adding New Bash Commands

To expand Claude Code's capabilities, edit .claude/settings.json and append new permission strings to the allow array. For example, to permit git status operations:

{
  "permissions": {
    "allow": [
      "Skill(job-application-assistant)",
      "Bash(bun run:*)",
      "Bash(python salary_lookup.py:*)",
      "Bash(python3 salary_lookup.py:*)",
      "Bash(python tools/verify_pdf.py:*)",
      "Bash(python3 tools/verify_pdf.py:*)",
      "Bash(pdftotext:*)",
      "Bash(git status:*)"
    ]
  }
}

Save the file and restart Claude Code or initiate a new command session to apply the changes.

Creating Local Overrides

For personal customization without modifying the shared repository settings, create .claude/settings.local.json in the same directory. This file merges on top of settings.json, allowing developers to add stricter or additional permissions individually:

{
  "permissions": {
    "allow": [
      "Bash(git diff:*)"
    ],
    "deny": [
      "Bash(python3 salary_lookup.py:*)"
    ]
  }
}

Since .claude/settings.local.json should not be committed to version control, it enables per-developer fine-tuning while maintaining the team's shared security baseline in settings.json.

Summary

  • Permission settings for Claude Code in ai-job-search are defined in .claude/settings.json at the repository root.
  • The model operates on default-deny principles, allowing only explicitly listed skills and bash commands.
  • Current permissions include the job-application-assistant skill and specific patterns for bun run, Python scripts (salary_lookup.py, verify_pdf.py), and pdftotext.
  • Local overrides can be created in .claude/settings.local.json for individual customization without affecting team-wide settings.
  • Changes to permission files require restarting Claude Code sessions to take effect.

Frequently Asked Questions

The central permission settings are stored in .claude/settings.json at the repository root, as implemented in the MadsLorentzen/ai-job-search repository. The SETUP.md documentation confirms this location defines shared, repository-scoped permissions for all Claude Code operations.

What happens if I try to run a command not listed in the allow array?

Claude Code will deny the execution. The ai-job-search configuration implements a default-deny security model where only commands explicitly listed in the permissions.allow array are permitted. Any bash command or skill not matching the defined patterns will be blocked.

Can I override permissions without modifying the shared settings file?

Yes, by creating .claude/settings.local.json in the same .claude directory. This personal configuration file merges with the shared settings.json, allowing you to add or restrict permissions for your local environment without committing changes to version control or affecting other developers.

Which specific bash commands are permitted in the current configuration?

According to the source code in .claude/settings.json, the following bash patterns are allowed: bun run:*, python salary_lookup.py:*, python3 salary_lookup.py:*, python tools/verify_pdf.py:*, python3 tools/verify_pdf.py:*, and pdftotext:*. These permissions support the repository's job application workflow automation while restricting general system access.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →