Localhost stays open.
Local MCP servers, your dev database, the model running on your machine — your agent talks to them with no holds, no prompts, no policy fiddling. localhost and 127.0.0.1 are in the default allow list and stay there until you remove them.