Tool Inventory Matrix
Inventory of MCP servers, tools, permissions, OAuth scopes, credentials, data touched, and allowed actions.
MCP & Tool-Use Blast-Radius Review
A technical review of Model Context Protocol servers, clients, tools, tokens, and approval paths before broad rollout.
Your LLM clients are gaining access to real tools, but the team cannot yet show which actions are permitted, which trust boundaries are crossed, or how destructive actions are contained.
Best fit: Platform, security, developer experience, and AI infrastructure teams adopting MCP or custom tool-use gateways.
MCP clients and servers, tool schemas, OAuth and delegated access, credentials, data flows, read/write/delete/send/execute permissions, approval gates, logging, and rate limits.
Deliverable
A tool inventory and trust-boundary review with a permission matrix, destructive-action control plan, blast-radius map, and prioritized scope-reduction roadmap.
Timeline
Typically 10 business days from kickoff and access confirmation.
Signature view / permission lattice
MCP risk becomes easier to discuss when every tool is classified by what it can do and paired with the control required before that action is allowed.
Can this identity see it?
Retrieve records, files, messages, or system state.
Can this identity change it?
Create or modify records, files, configurations, or tickets.
Can this action be recovered?
Remove data or resources where recovery may be limited.
Can this action leave the system?
Communicate externally through email, messaging, publishing, or transactions.
Can this action alter operations?
Run commands, deploy changes, approve workflows, or alter operations.
Sample assessment package
Agree the review boundary, authorized methods, and decision the work must support before starting. The scoped package draws from the outputs below and identifies untested paths and unresolved assumptions alongside the findings.
Inventory of MCP servers, tools, permissions, OAuth scopes, credentials, data touched, and allowed actions.
Analysis of MCP client/server trust, upstream APIs, token flow, session handling, and local-server exposure.
Classification of high-impact actions and required approval, policy, sandboxing, or hard-deny controls.
Clear explanation of what an abused agent/tool path can read, write, modify, delete, send, execute, or deploy.
Practical roadmap for least privilege, allowlists, user-scoped auth, egress limits, and tool-call logging.
Risk addressed
When to use it
Use this when LLM clients are being connected to internal systems, SaaS tools, file stores, ticketing systems, databases, or deployment workflows.
Next step