Skip to lesson
Exit
Inspect MCP from the CLI1 / 2

1 min lesson

Inspect and permit one analytics MCP

Inspect analytics-db, set exact CLI tool permissions and prove the allow, prompt and deny paths.

Step 1 of 2

Open the CLI server inventory and confirm that analytics-db is connected from the project config over stdio. Record the identifier exactly because the permission token uses that server name. If a name contains spaces, use the identifier as shown. Enabled means the server can load; it does not make every tool call automatic. Inspect the analytics-db tool list and read the description and argument schema for read_schema, run_readonly_query and apply_migration. Enable or authenticate the server only if its status requires it. In .cursor/cli.json, allow the exact read_schema token and deny the exact apply_migration token. Start an interactive CLI session and propose all three tools. read_schema should run without a prompt, run_readonly_query should ask and apply_migration should be denied. Keep the inventory, schemas, file and transcript together.

Learn more

Full explanation

Agent MCP list, list-tools and .cursor/cli.json

Inspect analytics-db and set exact CLI tool permissions
agent mcp list, list-tools and .cursor/cli.json
Sayanalytics-db works in the editor. Before using it from the terminal, confirm which definition the CLI found and what each tool can do.
Typeagent mcp list
DoOpen the CLI menu and find analytics-db. Check its connection status, configuration source and transport.
Seeanalytics-db is connected, comes from the project config and uses stdio. The CLI reads the same MCPModel Context Protocol. A standard that lets an AI agent pull in context from outside the repo, like Jira tickets or internal docs. Press Enter for the full definition. configuration as the editor.
Typeagent mcp list-tools analytics-db
DoRead every tool name, description and argument schema. Do not infer reach from the server name.
SeeThe list shows read_schema, run_readonly_query and apply_migration with their required and optional parameters.
DoIf the expected server is disabled, use agent mcp enable analytics-db. Use login only for a configured server that needs authentication. Disable any server this terminal task should not load.
SeeEnable adds the server to the local approved list. A disabled server does not load or prompt for approval.
Type{ "permissions": { "allow": ["Mcp(analytics-db:read_schema)"], "deny": ["Mcp(analytics-db:apply_migration)"] } }
DoSave the project CLI permissions in .cursor/cli.json. CLI permissions are separate from the editor's permissions.json, and deny entries take precedence over allow entries. Do not use --approve-mcps for this narrow task because it approves every configured MCPModel Context Protocol. A standard that lets an AI agent pull in context from outside the repo, like Jira tickets or internal docs. Press Enter for the full definition. server.
SeeOnly read_schema is allowed without a prompt. apply_migration is explicitly denied.
DoStart an interactive CLI session and propose read_schema, run_readonly_query and apply_migration. Inspect each tool call and keep the transcript.
Seeread_schema runs without a prompt, run_readonly_query asks for approval and apply_migration is denied. The transcript matches .cursor/cli.json.
Learn more

Optional practice

Test yourself on Inspect and permit one analytics MCP

QWhich result proves analytics-db is ready for controlled CLI use?