Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    mcp tool permission scoper

    1

    Generate evidence-based MCP tool allowlists and RBAC configs from historical agent usage logs.

    $12

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned
    mcp tool permission scoper

    mcp tool permission scoper

    Example session with this skill installed

    Analyze the last 60 days of logs for the 'analyst-bot' role and generate a Bifrost virtual-key JSON policy. It currently has full access to the 'postgres-server' and 'slack-server'.

    • Read your context and instructions
    • Compiled the mcp tool permission
    • Generated the document

    I have analyzed the tools/call logs for analyst-bot from 2024-06-01 to 2024-08-01. The role called 4 distinct tools across 2 servers. While the role currently holds * permissions, usage evidence suggests a significantly narrower scope.

    MCP Permission Audit & Bifrost Config

    FindingTool IDObservationsRecommendation
    Active Usepostgres-server:run_query142 callsRetain in allowlist
    Active Useslack-server:send_message28 callsRetain in allowlist
    Unused Grantpostgres-server:delete_table0 callsRemove (No usage in 60d)
    Unused Grantslack-server:admin_delete_channel0 callsRemove (No usage in 60d)
    Flaggedpostgres-server:dump_schema0 callsFlag (Potential monthly task)

    Generated Bifrost Policy (Least-Privilege)

    {
      "version": "2024-08-06",
      "role": "analyst-bot",
      "allowlist": [
        {
          "server": "postgres-server",
          "tools": ["run_query", "list_tables"]
        },
        {
          "server": "slack-server",
          "tools": ["send_message"]
        }
      ],
      "notes": "Generated from 60-day usage window. 'dump_schema' was excluded due to zero usage; add manually if required for reporting."
    }
    

    Next steps

    1. Review the Flagged tools to ensure no rare monthly reporting tasks are broken by this change.
    2. Apply the JSON to your Bifrost gateway configuration.
    3. Run mcp-gateway-config-auditor to verify the gateway is correctly enforcing these new tool restrictions.

    mcp-tool-permission-scoper.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Generate RBAC configs for Bifrost or agentgateway from usage history.Audit agent roles to justify trimming 'admin' grants with evidence.Identify shadow tool usage that bypasses current permission grants.Standardize tool scopes across multi-server MCP deployments.

    About this skill

    Most Model Context Protocol (MCP) deployments rely on human guesswork for tool permissions. Developers often grant broad scopes like `admin:*` to simple bots, creating massive security holes, or spend hours manually auditing logs to justify trimming access. This skill replaces guesswork with usage evidence. It analyzes your agent's `tools/call` history over a specific window to generate a least-privilege allowlist based on what the agent actually does, not what a human thinks it might do. ## What it does - **Log Attribution Validation** verifies that tool calls are tied to specific, authenticated identities before generating role-based scopes. - **Usage Analysis** pulls historical tool call data over a 90-day window to identify every server and tool interaction. - **Grant Diffing** compares observed tool usage against current permissions to highlight gaps, shadow access, or unused grants. - **Least-Privilege Scoping** generates an allowlist artifact that matches only the tools the agent successfully used. - **Disambiguation Mapping** keys permissions to `server_id:tool_name` to prevent scope leakage in multi-server environments. ## How it works 1. **Source Logs** are provided to the agent, covering a bounded observation window of historical tool activity. 2. **The Diagnostic Report** identifies tools that were called but not granted, and tools granted but never used. 3. **The Config Generator** produces a platform-specific RBAC artifact, such as Bifrost JSON or agentgateway CEL rules. 4. **The Review Cycle** presents the output as a diff for human approval, flagging rare break-glass tools for manual retention. ## Frameworks & tools Works with any MCP gateway or RBAC layer including Bifrost, agentgateway, Obot, and MCPManager. It targets the standard MCP `tools/list` and `tools/call` protocol specifications. ## Why this beats prompting it yourself Generic prompts often treat "never called" as "delete immediately," which breaks critical but rare incident-response tools. This skill follows the AWS IAM Access Analyzer precedent, using a formal request-review-refine loop and independent classification to protect rare-use paths while eliminating routine scope creep. ## Use cases - Generating a defensible starting allowlist when standing up a new MCP gateway. - Trimming broad grants from reporting bots that only need read access to three tools. - Automating periodic access-recertification cycles for internal agent fleets. - Justifying permission reductions with concrete usage evidence for security audits. ## Known limitations Cannot enforce policies; it only generates the configuration for a gateway to enforce. It is limited by the granularity of the target gateway and the attribution quality of the provided logs.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 2 days ago

    • Passed all security checks, Safe to install

    Needs access to

    Modelcontextprotocol

    Listed2 days ago

    What's inside

    Frequently Asked Questions