Core MCP Tool Safety
Review agent tool and MCP usage for credential scope, network egress, mutation risk, logging, and human approval gates.
Verified Surface
- Provider lane: core
- Native surface: SKILL.md skill packages
- Harness export: core
- Import mode: techtide-synthesis
- Source evidence: load
references/source-evidence.mdbefore promoting third-party material.
Workflow
- List each tool, host, credential class, filesystem path, and external mutation capability.
- Classify operations as read-only, workspace-write, external-read, or external-mutate.
- Require explicit approval for destructive filesystem, production, billing, messaging, or security changes.
- Verify secrets are never echoed, logged, or written into public artifacts.
- Document minimum privileges and safe fallback behavior.
Output Contract
Return:
- provider lane and native surface
- source evidence used
- promotion decision or operating recommendation
- security and privacy notes
- verification still required
Guardrails
- Keep third-party source bodies out of public artifacts unless direct import has clean license, attribution, and manual review.
- Do not use star counts, popularity, screenshots, or social posts as the sole evidence for promotion.
- Do not install or execute unreviewed external scripts as part of source research.
- Quarantine missing licenses, unclear ownership, vague prompt packs, duplicate skill packs, and unsupported native-surface claims.
- Preserve Alex Cinovoj / TechTide ownership for TechTide-authored synthesis while citing third-party sources as references.