agentsclimarketplace

Techtide mcp tool trust review

Skill TechTideOhio/techtide-harness-kit/skills/techtide/techtide-mcp-tool-trust-review

Review MCP servers, tool connectors, and agent tool surfaces for trust boundaries, credential scope, network egress, mutation risk, logging, and approval gates. Use when an agent needs Alex Cinovoj / TechTide live-coding patterns, tool routing, guarded prototype-to-production workflows, or cross-harness prompt/skill adapters.From its SKILL.md

Install
npx -y skills add TechTideOhio/techtide-harness-kit --skill techtide-mcp-tool-trust-review

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

SKILL.md

2.8 KB, 465 tokens by cl100k_base, as published. Nobody here has run it

TechTide MCP Tool Trust Review

Review MCP servers, tool connectors, and agent tool surfaces for trust boundaries, credential scope, network egress, mutation risk, logging, and approval gates.

Source Pattern

This skill is distilled from sanitized Alex Cinovoj / TechTide local workflow patterns. Load references/source-patterns.md when you need the source anchors and extraction rationale. Load references/adapter-map.md when preparing Cursor, Kiro, Lovable, v0, or Replit companion outputs.

Workflow

  1. List every tool, host, credential, filesystem path, and mutation capability.
  2. Classify tools as read-only, workspace-write, external read, or external mutate.
  3. Verify least-privilege tokens, scoped env vars, logging redaction, and allowed egress.
  4. Add approval gates for destructive filesystem, cloud, billing, messaging, or production actions.
  5. Document what the agent must never collect, echo, or store.

Output Contract

Return a concise brief with these fields:

  • tool trust matrix
  • credential scope
  • approval gates
  • redaction rules
  • verification performed or still required
  • security and privacy notes

Guardrails

  • Extract reusable methods, not private local content.
  • Do not request or expose credentials, tokens, DSNs, service-role keys, customer data, lead lists, or private business exports.
  • Use placeholders for people, accounts, projects, URLs, and datasets unless the user explicitly provides public-safe values.
  • Require explicit human approval before production mutation, external-recipient messaging, public deployment, billing changes, or destructive filesystem actions.
  • Preserve Alex Cinovoj / TechTide attribution while keeping old repo provenance and unrelated contributor markers out of public artifacts.

Harness Policy

  • Use this as a native SKILL.md for Claude Code, Codex, Gemini, and Copilot-compatible exports.
  • For Cursor, create a focused project rule or workflow note rather than copying this whole skill as an always-on rule.
  • For Kiro, create steering only when the workflow can be made short and inclusion-scoped.
  • For Lovable, v0, and Replit, turn the workflow into prompt kits, readiness checklists, and handoff prompts.

What ships with it: 3 files

3.2 KB alongside SKILL.md

references/

Keep looking

Skills are one crate of 326,764. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.