Core mcp tool safety
Skill TechTideOhio/techtide-harness-kit/skills/core/core-mcp-tool-safety
Trust contracts for AI agent skills: JSON Schema risk tiers, tool permissions, deny-by-default egress, approval gates, prompt-injection fixtures, ~28 CI validation gates. Apache-2.0.
npx -y skills add TechTideOhio/techtide-harness-kit --skill core-mcp-tool-safetyAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Review agent tool and MCP usage for credential scope, network egress, mutation risk, logging, and human approval gates. Use when expanding, reviewing, or operating skills, rules, prompt kits, provider lanes, or generated-code handoffs in the TechTide skill library.
SKILL.md
2.2 KB, as published. Nobody here has run it
Core MCP Tool Safety
Review agent tool and MCP usage for credential scope, network egress, mutation risk, logging, and human approval gates.
Verified Surface
- Provider lane: core
- Native surface: SKILL.md skill packages
- Harness export: core
- Import mode: techtide-synthesis
- Source evidence: load
references/source-evidence.mdbefore promoting third-party material.
Workflow
- List each tool, host, credential class, filesystem path, and external mutation capability.
- Classify operations as read-only, workspace-write, external-read, or external-mutate.
- Require explicit approval for destructive filesystem, production, billing, messaging, or security changes.
- Verify secrets are never echoed, logged, or written into public artifacts.
- Document minimum privileges and safe fallback behavior.
Output Contract
Return:
- provider lane and native surface
- source evidence used
- promotion decision or operating recommendation
- security and privacy notes
- verification still required
Guardrails
- Keep third-party source bodies out of public artifacts unless direct import has clean license, attribution, and manual review.
- Do not use star counts, popularity, screenshots, or social posts as the sole evidence for promotion.
- Do not install or execute unreviewed external scripts as part of source research.
- Quarantine missing licenses, unclear ownership, vague prompt packs, duplicate skill packs, and unsupported native-surface claims.
- Preserve Alex Cinovoj / TechTide ownership for TechTide-authored synthesis while citing third-party sources as references.