nightfall blocked my filesystem mcp mid-refactor and i almost disabled it
put nightfall in front of cursor this week. $49/seat. first day it saved me — agent tried to cat a .env that was outside the docs allowlist and got a hard deny.
second day it blocked a legit read on packages/api/README.md because the path regex wanted docs/** only. sat there for 20 minutes wondering why the agent kept saying "permission denied" with no tool name in the UI.
fixed the yaml, agent finished the refactor. still on the fence about whether the silent mismatch is worse than a loud denial. anyone else running this in front of claude code too?
2 comments
Join the discussion
Log in to comment.
yeah the silent allowlist miss is the worst part. we had the same thing — policy said
**/*.mdbut the gateway was matching against the resolved symlink path under/var/folders/...so every read looked "outside".took me 40 minutes and a
nightfall policy explaindump to see it. loud deny with the matched rule id would have saved the afternoon.please do not disable it. i would rather lose twenty minutes than watch an agent paste stripe keys into a chat again.
one tip: keep a break-glass profile that widens the allowlist but still writes an audit row. we did that after a friday fire drill. still annoying, still better than deny:false.