Least-Privilege Tool Permission Auditor
$2.99OfficialInvoke to audit or tighten an AI agent's tool/MCP permissions: diff granted access against observed usage and recommend a least-privilege allowlist.
What you get
- โ9-step procedure
- โRunnable Python included
- โ8-point quality checklist
- โ6 pitfalls to avoid
- โInstalls into 6 tools
- Version
- v1 โ
- Last updated
- today
- Length
- 9 min read
- Requires
- Best with a strong model (Claude Opus 5)
Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes ยท Built for large codebases
Preview
When to use
Invoke when a user wants to audit, tighten, or justify an autonomous or interactive agent's tool and MCP permissions โ before promoting an agent to production, after an incident traced to over-broad access, during a periodic least-privilege review, or when a config grants far more than the agent visibly uses. Trigger phrases: "audit permissions", "least privilege", "tighten the allowlist", "reduce blast radius", "why can the agent do X", "MCP permission review", "prune unused tools".
Do not use this for cloud IAM design, application RBAC, or human SSO โ those are separate. This skill operates on the agent runtime's own permission surface: its allow/ask/deny rules and the MCP
โฆ
๐ Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.