Open-source AI infrastructure

Agent Permission Broker

Least-privilege scope planning for tools, MCP servers, and agent chains.

JavaScript MIT licensed Offline by default Community extensible

Purpose

Agents often receive broad tools, broad tokens, and broad autonomy, turning model mistakes into real-world damage.

A scope planner that compares requested operations with minimal permissions, flags omnibus scopes, and recommends approval gates.

What it does

Validates a domain-specific AI governance packet, scores readiness, and returns concrete findings that contributors can improve.

Why it matters

AI systems are moving from chat into action. This project makes one hard operational risk easier to inspect, test, and govern in public.

Who should use it

Least-privilege scope planning for tools, MCP servers, and agent chains. Builders can start with the CLI, then add adapters, fixtures, schemas, and integrations.

Quick Start

npm test
npm start -- sample

Example Packet

{
  "task": "summarize invoices",
  "requestedScopes": [
    "email.read",
    "drive.read",
    "payments.write"
  ],
  "tools": [
    {
      "name": "drive",
      "operation": "read"
    },
    {
      "name": "payments",
      "operation": "none"
    }
  ]
}

Contribution Tracks

Good first issues

  • OAuth challenge helpers
  • MCP scope catalogs
  • policy diffing
  • agent-chain delegation maps

Core improvements

  • Add JSON Schema validation.
  • Add more real-world, non-sensitive fixtures.
  • Improve scoring transparency and edge-case tests.

Integration work

  • Build adapters for common AI frameworks.
  • Add CI checks and report exports.
  • Connect the packet format to operational workflows.