なぜ設定するのか

deny に書いたファイルは検索結果から外れ、読み取りも Edit / Write もブロックされます。deny はどの権限モード(bypassPermissions を含む)でも効くので、最後の砦として置いておけます。

Read の deny は Claude の Read ツールに対する制限です。Bash 経由の cat まで確実に止めたいなら sandbox も併用します。

設定方法

  1. ~/.claude/settings.json を開く(なければ作る)
  2. スニペットを JSON の中に統合する。既存の設定は消さず、キーを足す形で入れる
  3. Claude Code を起動し直す
既定値
未設定(制限なし)
書く場所
~/.claude/settings.json
型
array of permission rule strings
置ける場所
Any file

公式ドキュメントの説明

List the tool uses Claude Code blocks. Use it for files that hold API keys, secrets, or environment values: Claude Code excludes matching files from file discovery and search results, denies reads of them, and blocks the Edit and Write tools on the matching paths.

公式リファレンスを見る