# Core MCP Tool Safety

> Review agent tool and MCP usage for credential scope, network egress, mutation risk, logging, and human approval gates. Use when expanding, reviewing, or operating skills, rules, prompt kits, provider lanes, or generated-code handoffs in the TechTide skill library.

- Skill: `techtideohio/core-mcp-tool-safety` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add techtideohio/core-mcp-tool-safety`
- Raw SKILL.md: https://api.skillmd.com/api/skills/techtideohio/core-mcp-tool-safety/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: AI & ML
- Author: TechTideOhio (https://skillmd.com/u/techtideohio)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/techtideohio/core-mcp-tool-safety

---


# Core MCP Tool Safety

Review agent tool and MCP usage for credential scope, network egress, mutation risk, logging, and human approval gates.

## Verified Surface

- Provider lane: core
- Native surface: SKILL.md skill packages
- Harness export: core
- Import mode: techtide-synthesis
- Source evidence: load `references/source-evidence.md` before promoting third-party material.

## Workflow

1. List each tool, host, credential class, filesystem path, and external mutation capability.
2. Classify operations as read-only, workspace-write, external-read, or external-mutate.
3. Require explicit approval for destructive filesystem, production, billing, messaging, or security changes.
4. Verify secrets are never echoed, logged, or written into public artifacts.
5. Document minimum privileges and safe fallback behavior.

## Output Contract

Return:

- provider lane and native surface
- source evidence used
- promotion decision or operating recommendation
- security and privacy notes
- verification still required

## Guardrails

- Keep third-party source bodies out of public artifacts unless direct import has clean license, attribution, and manual review.
- Do not use star counts, popularity, screenshots, or social posts as the sole evidence for promotion.
- Do not install or execute unreviewed external scripts as part of source research.
- Quarantine missing licenses, unclear ownership, vague prompt packs, duplicate skill packs, and unsupported native-surface claims.
- Preserve Alex Cinovoj / TechTide ownership for TechTide-authored synthesis while citing third-party sources as references.

