Project Trust
A repository can contain configuration that makes Elyra run code on your machine. Elyra only honors that configuration after you have trusted the project directory, so cloning and opening a repository is safe.
What is gated
These only take effect in trusted projects:
| Configuration | Why it is gated |
|---|---|
packages in .elyra/settings.json |
npm and git packages are installed on startup, which runs their install scripts |
extensions in .elyra/settings.json and files in .elyra/extensions/ |
Extensions are loaded as code |
.mcp.json, .elyra/mcp.json, .cursor/mcp.json, .vscode/mcp.json |
MCP server definitions start processes |
shellPath, shellCommandPrefix, npmCommand in project settings |
They change how every command runs |
autoExtensions, autoSkills in project settings |
They remove approval prompts |
Everything else in a project works as usual, trusted or not: AGENTS.md, CLAUDE.md, skills, prompt templates, themes, and all other settings. Those are read by the model and cannot run anything without going through the agent's own tools.
A project with none of the gated configuration never asks for trust.
The prompt
When you start Elyra in a project that contains gated configuration, it lists exactly what would run and asks:
- Trust this folder. Remembered for this directory and everything below it.
- Trust parent folder. Remembered for the parent, which covers every project inside it. Useful for a directory such as
~/Codethat only holds your own repositories. - Trust for this session only. Nothing is saved.
- Continue without project code. Elyra runs normally but skips the gated items and says so.
Only trust projects you know.
Changing your mind
Inside Elyra:
/trust review what the project loads, and trust it (reloads in place)
/trust revoke stop trusting this project
/trust list list trusted directories
From the shell:
elyra trust # trust the current directory
elyra trust ~/Code # trust a directory and everything below it
elyra trust --status # show the decision and what the project would load
elyra trust --list
elyra trust --revoke [path]
Trusted directories are stored in ~/.elyra/agent/trusted-projects.json.
elyra install -l <source> trusts the current project automatically, since adding a project package yourself is an explicit decision.
Scripts, CI, and other modes
Print mode (-p), JSON mode, RPC mode, and MCP server mode never prompt. In an untrusted project they run without the gated configuration and print a warning. To trust the project for one run:
elyra --trust-project -p "run the checks"
ELYRA_TRUST_PROJECT=1 elyra -p "run the checks"
Child agents
Extensions that start child Elyra processes, such as @elyracode/swarm, pass the parent's trust decision to the child through ctx.getChildAgentEnv(). A swarm stage running in a temporary git worktree therefore loads the same project configuration as the session that started it. The decision is removed from the child's environment at startup, so commands the agent runs do not inherit it.
For extension authors
Extensions that execute configuration found in the project (MCP servers, workflow commands, hooks) must check ctx.isProjectTrusted() and refuse while it returns false. Tell the user to run /trust.
SDK hosts decide trust themselves: pass resolveProjectTrust to createAgentSessionServices(), or call settingsManager.setProjectTrusted(false) before resources load. Without either, the SDK trusts the project, as before.