Elyra
Elyra The coding agent eTerm The terminal that knows where each command ends Starf An activity monitor for Apple silicon that never invents a number Litr A small, native web browser for macOS Notr A notebook for macOS e The native code editor Elyra Grove Native local development environment Askr The real server for Laravel & PHP Elyra Framework Rust + Svelte 5 framework for desktop apps Elyra Conductor Local project conductor Refr Local-first PDF workspace for macOS Elyra SQL Server MySQL-compatible SQL server in Rust Elyra Félagi Agents as teammates on one board Elyra SQL Client Native desktop SQL workbench Elyra SQL Anywhere Replication-ready SQL engine Elyra Sjá SEO & GEO workspace for macOS Elyra DataGrid Server-driven data grid for Laravel
Development
Development
Release notes
Changelog
Elyra
Project Trust

Project Trust

A repository can contain configuration that makes Elyra run code on your machine. Elyra only honors that configuration after you have trusted the project directory, so cloning and opening a repository is safe.

What is gated

These only take effect in trusted projects:

Configuration Why it is gated
packages in .elyra/settings.json npm and git packages are installed on startup, which runs their install scripts
extensions in .elyra/settings.json and files in .elyra/extensions/ Extensions are loaded as code
.mcp.json, .elyra/mcp.json, .cursor/mcp.json, .vscode/mcp.json MCP server definitions start processes
shellPath, shellCommandPrefix, npmCommand in project settings They change how every command runs
autoExtensions, autoSkills in project settings They remove approval prompts

Everything else in a project works as usual, trusted or not: AGENTS.md, CLAUDE.md, skills, prompt templates, themes, and all other settings. Those are read by the model and cannot run anything without going through the agent's own tools.

A project with none of the gated configuration never asks for trust.

The prompt

When you start Elyra in a project that contains gated configuration, it lists exactly what would run and asks:

  • Trust this folder. Remembered for this directory and everything below it.
  • Trust parent folder. Remembered for the parent, which covers every project inside it. Useful for a directory such as ~/Code that only holds your own repositories.
  • Trust for this session only. Nothing is saved.
  • Continue without project code. Elyra runs normally but skips the gated items and says so.

Only trust projects you know.

Changing your mind

Inside Elyra:

/trust          review what the project loads, and trust it (reloads in place)
/trust revoke   stop trusting this project
/trust list     list trusted directories

From the shell:

elyra trust                 # trust the current directory
elyra trust ~/Code          # trust a directory and everything below it
elyra trust --status        # show the decision and what the project would load
elyra trust --list
elyra trust --revoke [path]

Trusted directories are stored in ~/.elyra/agent/trusted-projects.json.

elyra install -l <source> trusts the current project automatically, since adding a project package yourself is an explicit decision.

Scripts, CI, and other modes

Print mode (-p), JSON mode, RPC mode, and MCP server mode never prompt. In an untrusted project they run without the gated configuration and print a warning. To trust the project for one run:

elyra --trust-project -p "run the checks"
ELYRA_TRUST_PROJECT=1 elyra -p "run the checks"

Child agents

Extensions that start child Elyra processes, such as @elyracode/swarm, pass the parent's trust decision to the child through ctx.getChildAgentEnv(). A swarm stage running in a temporary git worktree therefore loads the same project configuration as the session that started it. The decision is removed from the child's environment at startup, so commands the agent runs do not inherit it.

For extension authors

Extensions that execute configuration found in the project (MCP servers, workflow commands, hooks) must check ctx.isProjectTrusted() and refuse while it returns false. Tell the user to run /trust.

SDK hosts decide trust themselves: pass resolveProjectTrust to createAgentSessionServices(), or call settingsManager.setProjectTrusted(false) before resources load. Without either, the SDK trusts the project, as before.