Works with the AI tools you already use
mcp tool permission scoper
Generate evidence-based MCP tool allowlists and RBAC configs from historical agent usage logs.
$12
mcp tool permission scoper
Example session with this skill installed
Analyze the last 60 days of logs for the 'analyst-bot' role and generate a Bifrost virtual-key JSON policy. It currently has full access to the 'postgres-server' and 'slack-server'.
- Read your context and instructions
- Compiled the mcp tool permission
- Generated the document
I have analyzed the tools/call logs for analyst-bot from 2024-06-01 to 2024-08-01. The role called 4 distinct tools across 2 servers. While the role currently holds * permissions, usage evidence suggests a significantly narrower scope.
MCP Permission Audit & Bifrost Config
| Finding | Tool ID | Observations | Recommendation |
|---|---|---|---|
| Active Use | postgres-server:run_query | 142 calls | Retain in allowlist |
| Active Use | slack-server:send_message | 28 calls | Retain in allowlist |
| Unused Grant | postgres-server:delete_table | 0 calls | Remove (No usage in 60d) |
| Unused Grant | slack-server:admin_delete_channel | 0 calls | Remove (No usage in 60d) |
| Flagged | postgres-server:dump_schema | 0 calls | Flag (Potential monthly task) |
Generated Bifrost Policy (Least-Privilege)
{
"version": "2024-08-06",
"role": "analyst-bot",
"allowlist": [
{
"server": "postgres-server",
"tools": ["run_query", "list_tables"]
},
{
"server": "slack-server",
"tools": ["send_message"]
}
],
"notes": "Generated from 60-day usage window. 'dump_schema' was excluded due to zero usage; add manually if required for reporting."
}
Next steps
- Review the Flagged tools to ensure no rare monthly reporting tasks are broken by this change.
- Apply the JSON to your Bifrost gateway configuration.
- Run
mcp-gateway-config-auditorto verify the gateway is correctly enforcing these new tool restrictions.
mcp-tool-permission-scoper.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Most Model Context Protocol (MCP) deployments rely on human guesswork for tool permissions. Developers often grant broad scopes like `admin:*` to simple bots, creating massive security holes, or spend hours manually auditing logs to justify trimming access. This skill replaces guesswork with usage evidence. It analyzes your agent's `tools/call` history over a specific window to generate a least-privilege allowlist based on what the agent actually does, not what a human thinks it might do. ## What it does - **Log Attribution Validation** verifies that tool calls are tied to specific, authenticated identities before generating role-based scopes. - **Usage Analysis** pulls historical tool call data over a 90-day window to identify every server and tool interaction. - **Grant Diffing** compares observed tool usage against current permissions to highlight gaps, shadow access, or unused grants. - **Least-Privilege Scoping** generates an allowlist artifact that matches only the tools the agent successfully used. - **Disambiguation Mapping** keys permissions to `server_id:tool_name` to prevent scope leakage in multi-server environments. ## How it works 1. **Source Logs** are provided to the agent, covering a bounded observation window of historical tool activity. 2. **The Diagnostic Report** identifies tools that were called but not granted, and tools granted but never used. 3. **The Config Generator** produces a platform-specific RBAC artifact, such as Bifrost JSON or agentgateway CEL rules. 4. **The Review Cycle** presents the output as a diff for human approval, flagging rare break-glass tools for manual retention. ## Frameworks & tools Works with any MCP gateway or RBAC layer including Bifrost, agentgateway, Obot, and MCPManager. It targets the standard MCP `tools/list` and `tools/call` protocol specifications. ## Why this beats prompting it yourself Generic prompts often treat "never called" as "delete immediately," which breaks critical but rare incident-response tools. This skill follows the AWS IAM Access Analyzer precedent, using a formal request-review-refine loop and independent classification to protect rare-use paths while eliminating routine scope creep. ## Use cases - Generating a defensible starting allowlist when standing up a new MCP gateway. - Trimming broad grants from reporting bots that only need read access to three tools. - Automating periodic access-recertification cycles for internal agent fleets. - Justifying permission reductions with concrete usage evidence for security audits. ## Known limitations Cannot enforce policies; it only generates the configuration for a gateway to enforce. It is limited by the granularity of the target gateway and the attribution quality of the provided logs.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 2 days ago
- Passed all security checks, Safe to install
Needs access to