Auto run deny all commands

I want to enable auto run just for MCP, do not allow anything else, I tried putting wildcard into deny command list, which would only allow MCP calls but it does not work, can something like that be implemented?

any chance of this being implemented?