1 min lesson
Inspect and permit one analytics MCP
Inspect analytics-db, set exact CLI tool permissions and prove the allow, prompt and deny paths.
Step 1 of 2
Open the CLI server inventory and confirm that analytics-db is connected from the project config over stdio. Record the identifier exactly because the permission token uses that server name. If a name contains spaces, use the identifier as shown. Enabled means the server can load; it does not make every tool call automatic. Inspect the analytics-db tool list and read the description and argument schema for read_schema, run_readonly_query and apply_migration. Enable or authenticate the server only if its status requires it. In .cursor/cli.json, allow the exact read_schema token and deny the exact apply_migration token. Start an interactive CLI session and propose all three tools. read_schema should run without a prompt, run_readonly_query should ask and apply_migration should be denied. Keep the inventory, schemas, file and transcript together.
Learn more
Full explanation
Agent MCP list, list-tools and .cursor/cli.json
agent mcp listagent mcp list-tools analytics-db{
"permissions": {
"allow": ["Mcp(analytics-db:read_schema)"],
"deny": ["Mcp(analytics-db:apply_migration)"]
}
}Learn more
Optional practice
Test yourself on Inspect and permit one analytics MCP
QWhich result proves analytics-db is ready for controlled CLI use?