Skip to main content

mcp-trust-broker

Vet a third-party MCP server before it can run: install-card completeness (manifest, provenance, permission label, health check, disable/repair/uninstall, usage trace), signature verification, least-privilege capability mapping, a sandbox smoke test, quarantine-until-reviewed, and team allow/approve/block policy. Use when a new MCP server is discovered or proposed for the fleet's tool palette, when a server requests to exit quarantine and run for real, or when auditing whether an MCP install card meets the minimum contract. NOT for general ocap/mTLS/capability-crypto theory (use agentic-zero-trust-security), building your own MCP server from scratch (a separate authoring concern this skill does not cover), proving a sandbox boundary itself withstands adversarial attack (use sandboxed-adversarial-test-harness), or the event-trigger-to-agent-spawn trust gate for inbound webhooks/email/SMS (use fleet-event-spawn-trust).

الانتقال إلى التثبيت

معلومات المصدر

المستودع
curiositech/port-daddy
آخر نشاط في المصدر
٤ يوليو ٢٠٢٦ في ٠٨:٤٨
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
٢
التفرعات
٠

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.