Purpose
Agents often receive broad tools, broad tokens, and broad autonomy, turning model mistakes into real-world damage.
A scope planner that compares requested operations with minimal permissions, flags omnibus scopes, and recommends approval gates.
What it does
Validates a domain-specific AI governance packet, scores readiness, and returns concrete findings that contributors can improve.
Why it matters
AI systems are moving from chat into action. This project makes one hard operational risk easier to inspect, test, and govern in public.
Who should use it
Least-privilege scope planning for tools, MCP servers, and agent chains. Builders can start with the CLI, then add adapters, fixtures, schemas, and integrations.
Quick Start
npm test
npm start -- sample
Example Packet
{
"task": "summarize invoices",
"requestedScopes": [
"email.read",
"drive.read",
"payments.write"
],
"tools": [
{
"name": "drive",
"operation": "read"
},
{
"name": "payments",
"operation": "none"
}
]
}
Contribution Tracks
Good first issues
- OAuth challenge helpers
- MCP scope catalogs
- policy diffing
- agent-chain delegation maps
Core improvements
- Add JSON Schema validation.
- Add more real-world, non-sensitive fixtures.
- Improve scoring transparency and edge-case tests.
Integration work
- Build adapters for common AI frameworks.
- Add CI checks and report exports.
- Connect the packet format to operational workflows.