TechTide MCP Tool Trust Review
Review MCP servers, tool connectors, and agent tool surfaces for trust boundaries, credential scope, network egress, mutation risk, logging, and approval gates.
Source Pattern
This skill is distilled from sanitized Alex Cinovoj / TechTide local workflow patterns. Load references/source-patterns.md when you need the source anchors and extraction rationale. Load references/adapter-map.md when preparing Cursor, Kiro, Lovable, v0, or Replit companion outputs.
Workflow
- List every tool, host, credential, filesystem path, and mutation capability.
- Classify tools as read-only, workspace-write, external read, or external mutate.
- Verify least-privilege tokens, scoped env vars, logging redaction, and allowed egress.
- Add approval gates for destructive filesystem, cloud, billing, messaging, or production actions.
- Document what the agent must never collect, echo, or store.
Output Contract
Return a concise brief with these fields:
- tool trust matrix
- credential scope
- approval gates
- redaction rules
- verification performed or still required
- security and privacy notes
Guardrails
- Extract reusable methods, not private local content.
- Do not request or expose credentials, tokens, DSNs, service-role keys, customer data, lead lists, or private business exports.
- Use placeholders for people, accounts, projects, URLs, and datasets unless the user explicitly provides public-safe values.
- Require explicit human approval before production mutation, external-recipient messaging, public deployment, billing changes, or destructive filesystem actions.
- Preserve Alex Cinovoj / TechTide attribution while keeping old repo provenance and unrelated contributor markers out of public artifacts.
Harness Policy
- Use this as a native
SKILL.md for Claude Code, Codex, Gemini, and Copilot-compatible exports.
- For Cursor, create a focused project rule or workflow note rather than copying this whole skill as an always-on rule.
- For Kiro, create steering only when the workflow can be made short and inclusion-scoped.
- For Lovable, v0, and Replit, turn the workflow into prompt kits, readiness checklists, and handoff prompts.
1---2name: techtide-mcp-tool-trust-review3description: Review MCP servers, tool connectors, and agent tool surfaces for trust boundaries, credential scope, network egress, mutation risk, logging, and approval gates. Use when an agent needs Alex Cinovoj / TechTide live-coding patterns, tool routing, guarded prototype-to-production workflows, or cross-harness prompt/skill adapters.4---56# TechTide MCP Tool Trust Review78Review MCP servers, tool connectors, and agent tool surfaces for trust boundaries, credential scope, network egress, mutation risk, logging, and approval gates.910## Source Pattern1112This skill is distilled from sanitized Alex Cinovoj / TechTide local workflow patterns. Load `references/source-patterns.md` when you need the source anchors and extraction rationale. Load `references/adapter-map.md` when preparing Cursor, Kiro, Lovable, v0, or Replit companion outputs.1314## Workflow15161. List every tool, host, credential, filesystem path, and mutation capability.172. Classify tools as read-only, workspace-write, external read, or external mutate.183. Verify least-privilege tokens, scoped env vars, logging redaction, and allowed egress.194. Add approval gates for destructive filesystem, cloud, billing, messaging, or production actions.205. Document what the agent must never collect, echo, or store.2122## Output Contract2324Return a concise brief with these fields:2526- tool trust matrix27- credential scope28- approval gates29- redaction rules30- verification performed or still required31- security and privacy notes3233## Guardrails3435- Extract reusable methods, not private local content.36- Do not request or expose credentials, tokens, DSNs, service-role keys, customer data, lead lists, or private business exports.37- Use placeholders for people, accounts, projects, URLs, and datasets unless the user explicitly provides public-safe values.38- Require explicit human approval before production mutation, external-recipient messaging, public deployment, billing changes, or destructive filesystem actions.39- Preserve Alex Cinovoj / TechTide attribution while keeping old repo provenance and unrelated contributor markers out of public artifacts.4041## Harness Policy4243- Use this as a native `SKILL.md` for Claude Code, Codex, Gemini, and Copilot-compatible exports.44- For Cursor, create a focused project rule or workflow note rather than copying this whole skill as an always-on rule.45- For Kiro, create steering only when the workflow can be made short and inclusion-scoped.46- For Lovable, v0, and Replit, turn the workflow into prompt kits, readiness checklists, and handoff prompts.