Home / The model / The capabilities / read.file.project

read.file.project

Read the project it is working on. Verb read, object file, reach project, family filesystem. Its effect is yes: undone.

In 7 of 9 published shapes

Deployment shapeBarrier thereKnown byNote
Claude Code on the web (a remote session container)none (not a control)observedthe attached working tree is readable
Claude Code (the CLI, on your own machine)none (not a control)derived
Claude Code (the CLI, on your own machine)none (not a control)derived
Claude Desktop (a desktop app with local tools)none (not a control)derivedwhat you paste or attach
Claude (in the browser, with connectors switched on)none (not a control)derived
Actions runner (a hosted CI job)none (not a control)observedthe checked-out tree at this ref is readable - including anything a contributor committed by mistake
ChatGPT (in the browser, no connectors)none (not a control)derivedwhat you paste or upload - and a record once read is exposure that cannot be unread, on the vendor's side
BarrierWhat stands in the wayIs it a control
nonenothing in the wayno
expectationa rule in prose, enforced by nobodyno
settinga switch the agent's own account can flipno
boundaryenforced above the grant, out of the agent's reachyes

What the starting mandates say about it

The mandate saysWhich mandates
authorisedA coding assistant on my machine, A coding assistant in a container on the web, The desktop app, with local tools switched on, Chat, with connectors switched on, Chat in the browser, nothing connected, A CI job on a hosted runner
refusednone
unstatedA browser extension I installed, A scheduled job under a service account

Unstated is not authorised. A mandate that never mentioned a capability did not authorise it, and the delta on every example page counts it as excess and says which kind it was.

What would move it to the fourth barrier

WhatWhat it costsThe barrier afterwards
none: this is what it is fornothingnone
This is a published reduction, not a recommendation. Whether it is worth doing depends on the assets and the consequences, which are not in this document and are not this site's to guess.

The capability grammar · This primitive as JSON