Toolwarrant
Import MCP tool manifests locally, map impact and input breadth, design least-privilege profiles, and mark where human approval belongs.
Focused field tools
Record every tool, server, purpose, owner, and runtime identity.
Separate observation, mutation, execution, communication, purchase, and deletion.
Constrain paths, hosts, repositories, recipients, amounts, and command families.
Use audience-bound credentials with minimum scopes and short lifetime.
Place informed human confirmation before consequential side effects.
Separate untrusted content from secrets, network, shell, and writable storage.
Toolwarrant reviews declared tool metadata and human-entered assumptions; it does not execute tools, inspect server code, enforce policy, or guarantee agent safety. Validate authentication, scopes, runtime isolation, prompts, arguments, side effects, logs, and approval behavior in the real system.