# Techtide MCP Tool Trust Review

> Review MCP servers, tool connectors, and agent tool surfaces for trust boundaries, credential scope, network egress, mutation risk, logging, and approval gates. Use when an agent needs Alex Cinovoj / TechTide live-coding patterns, tool routing, guarded prototype-to-production workflows, or cross-harness prompt/skill adapters.

- Skill: `techtideohio/techtide-mcp-tool-trust-review` (Agent Skill, multi-file: 4 files)
- Install (CLI): `npx skillmds@latest add techtideohio/techtide-mcp-tool-trust-review`
- Raw SKILL.md: https://api.skillmd.com/api/skills/techtideohio/techtide-mcp-tool-trust-review/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: AI & ML
- Author: TechTideOhio (https://skillmd.com/u/techtideohio)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/techtideohio/techtide-mcp-tool-trust-review

---


# TechTide MCP Tool Trust Review

Review MCP servers, tool connectors, and agent tool surfaces for trust boundaries, credential scope, network egress, mutation risk, logging, and approval gates.

## Source Pattern

This skill is distilled from sanitized Alex Cinovoj / TechTide local workflow patterns. Load `references/source-patterns.md` when you need the source anchors and extraction rationale. Load `references/adapter-map.md` when preparing Cursor, Kiro, Lovable, v0, or Replit companion outputs.

## Workflow

1. List every tool, host, credential, filesystem path, and mutation capability.
2. Classify tools as read-only, workspace-write, external read, or external mutate.
3. Verify least-privilege tokens, scoped env vars, logging redaction, and allowed egress.
4. Add approval gates for destructive filesystem, cloud, billing, messaging, or production actions.
5. Document what the agent must never collect, echo, or store.

## Output Contract

Return a concise brief with these fields:

- tool trust matrix
- credential scope
- approval gates
- redaction rules
- verification performed or still required
- security and privacy notes

## Guardrails

- Extract reusable methods, not private local content.
- Do not request or expose credentials, tokens, DSNs, service-role keys, customer data, lead lists, or private business exports.
- Use placeholders for people, accounts, projects, URLs, and datasets unless the user explicitly provides public-safe values.
- Require explicit human approval before production mutation, external-recipient messaging, public deployment, billing changes, or destructive filesystem actions.
- Preserve Alex Cinovoj / TechTide attribution while keeping old repo provenance and unrelated contributor markers out of public artifacts.

## Harness Policy

- Use this as a native `SKILL.md` for Claude Code, Codex, Gemini, and Copilot-compatible exports.
- For Cursor, create a focused project rule or workflow note rather than copying this whole skill as an always-on rule.
- For Kiro, create steering only when the workflow can be made short and inclusion-scoped.
- For Lovable, v0, and Replit, turn the workflow into prompt kits, readiness checklists, and handoff prompts.

