What
Permission rules are settings that allow, ask about or deny particular tool uses. For the Artifacts tool's list action, deny rules are now checked on every listing, and ask rules after them. Before, rules were only checked when artifacts were listed by type with no scope given.
A new denial message is shown on this general path. The shared code that matches rules gets the same extra matching step.
Why
A deny or ask rule you write for Artifacts listings now covers all listings. It no longer applies only to one narrow form of request.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
The finding does not say what the extra rule matcher matches beyond the existing one.