Skip to content
ModulesModule 06

Agent Trust MCP Security

Treat an MCP server as a privileged dependency: inventoried, risk-classified, approved, and watched for the capabilities it gains after approval.

Which MCP servers does it use, and what do they grant?Phase 3 · MCP and supply chain

What it does

Capabilities

  • A registry of MCP servers with publisher, version, hosting, tools, resources, scopes, data access and the agents using each
  • An approval path from discovery through publisher verification, tool inventory, permission analysis, scan and risk score
  • Per-tool risk classification, because search_files and run_shell are not the same grant
  • Permission drift detection when a server quietly adds a capability it did not ship with

What it leaves behind

Evidence produced

  • An approval record per server, and the agents that depend on it
  • A reauthorization demand when a server materially changes

Specification

Where this is specified

One blueprint page carries the full specification for this module.

13 modules and services make up the platform. See how they fit together.