Serveur MCP

Agent Utility MCP

io.github.insivotron/agent-utility-mcp
Outils développeur Sécurité Public et accessible MCP 2025-11-25

Ce que fait ce MCP

Performs deterministic preflight risk analysis for agent tool calls, shell commands, URLs, and files before execution.

analyze_tool_call
Analyze a proposed AI-agent tool call before execution and return a deterministic, policy-aware decision (allow, notice, confirm or block) covering destructive actions, sensitive-data exposure, external transmission, privilege changes and irreversible operations, under the applicable policy — permissive, balanced or strict, balanced by default. Filesystem paths outside a known workspace_root are treated as higher risk than paths inside it.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['tool_name', 'arguments'], 'properties': {'policy': {'enum': ['permissive', 'balanced', 'strict'], 'type': 'string', 'description': 'Optional policy used to compute the decision: permissive, balanced or strict (default: balanced).'}, 'context': {'type': 'object', 'properties': {'operation': {'type': 'string', 'maxLength': 4096}, 'description': {'type': 'string', 'maxLength': 4096}, 'destination': {'type': 'string', 'maxLength': 4096}, 'target_type': {'type': 'string', 'maxLength': 4096}, 'workspace_root': {'type': 'string', 'maxLength': 4096, 'description': 'Optional workspace root. Filesystem paths that resolve outside it are treated as higher risk than paths inside it.'}}, 'description': 'Optional declarative context about the proposed operation.', 'additionalProperties': False}, 'arguments': {'anyOf': [{'type': 'object', 'additionalProperties': {}}, {'type': 'array', 'items': {}}, {'type': 'string'}, {'type': 'number'}, {'type': 'boolean'}, {'type': 'null'}], 'description': 'The proposed tool arguments. They are analyzed as data and never executed.'}, 'tool_name': {'type': 'string', 'maxLength': 256, 'minLength': 1, 'description': 'The exact name of the proposed tool.'}}, 'additionalProperties': False}
Schéma de sortie
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['valid', 'tool_name', 'risk', 'risk_score', 'decision', 'policy_applied', 'ruleset_version', 'schema_version', 'context_completeness', 'signals', 'checks'], 'properties': {'risk': {'enum': ['safe', 'low', 'medium', 'high', 'critical'], 'type': 'string'}, 'valid': {'type': 'boolean'}, 'checks': {'type': 'object', 'required': ['destructive_action', 'irreversible_action', 'privilege_change', 'permission_change', 'sensitive_data_present', 'possible_secret_exposure', 'external_destination', 'possible_exfiltration', 'financial_action', 'communication_action', 'account_or_identity_action', 'code_execution', 'filesystem_mutation', 'network_action'], 'properties': {'code_execution': {'type': 'boolean'}, 'network_action': {'type': 'boolean'}, 'financial_action': {'type': 'boolean'}, 'privilege_change': {'type': 'boolean'}, 'permission_change': {'type': 'boolean'}, 'destructive_action': {'type': 'boolean'}, 'filesystem_mutation': {'type': 'boolean'}, 'irreversible_action': {'type': 'boolean'}, 'communication_action': {'type': 'boolean'}, 'external_destination': {'type': 'boolean'}, 'possible_exfiltration': {'type': 'boolean'}, 'sensitive_data_present': {'type': 'boolean'}, 'possible_secret_exposure': {'type': 'boolean'}, 'account_or_identity_action': {'type': 'boolean'}}, 'additionalProperties': False}, 'signals': {'type': 'array', 'items': {'type': 'object', 'required': ['code', 'severity', 'score', 'message'], 'properties': {'code': {'type': 'string'}, 'score': {'type': 'number'}, 'message': {'type': 'string'}, 'severity': {'enum': ['info', 'low', 'medium', 'high', 'critical'], 'type': 'string'}}, 'additionalProperties': False}}, 'decision': {'enum': ['allow', 'notice', 'confirm', 'block'], 'type': 'string'}, 'tool_name': {'type': ['string', 'null']}, 'risk_score': {'type': 'number'}, 'policy_applied': {'enum': ['permissive', 'balanced', 'strict'], 'type': 'string'}, 'schema_version': {'type': 'string'}, 'ruleset_version': {'type': 'string'}, 'context_completeness': {'enum': ['full', 'partial', 'none'], 'type': 'string'}}, 'additionalProperties': False}
analyze_url_risk
Analyze a URL for structural and security risk signals and return a deterministic, policy-aware decision (allow, notice, confirm or block) under the applicable policy — permissive, balanced or strict, balanced by default.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['url'], 'properties': {'url': {'type': 'string', 'minLength': 1, 'description': 'The absolute URL to analyze.'}, 'policy': {'enum': ['permissive', 'balanced', 'strict'], 'type': 'string', 'description': 'Optional policy used to compute the decision: permissive, balanced or strict (default: balanced).'}, 'context': {'type': 'object', 'properties': {'workspace_root': {'type': 'string', 'description': 'Accepted for contract consistency; URL analysis has no filesystem paths to scope, so it has no effect here.'}}, 'description': 'Optional declarative context.', 'additionalProperties': False}}, 'additionalProperties': False}
Schéma de sortie
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['valid', 'input', 'normalized_url', 'hostname', 'domain', 'public_suffix', 'subdomain', 'protocol', 'port', 'risk', 'risk_score', 'decision', 'policy_applied', 'ruleset_version', 'schema_version', 'context_completeness', 'signals', 'checks'], 'properties': {'port': {'type': ['string', 'null']}, 'risk': {'enum': ['safe', 'low', 'medium', 'high', 'critical'], 'type': 'string'}, 'input': {'type': 'string'}, 'valid': {'type': 'boolean'}, 'checks': {'type': 'object', 'required': ['dangerous_scheme', 'embedded_credentials', 'raw_ip_host', 'private_or_local_host', 'cloud_metadata_host', 'unicode_or_punycode_host', 'suspicious_port', 'excessive_subdomains', 'suspicious_keywords', 'executable_path', 'url_shortener', 'excessive_length'], 'properties': {'raw_ip_host': {'type': 'boolean'}, 'url_shortener': {'type': 'boolean'}, 'executable_path': {'type': 'boolean'}, 'suspicious_port': {'type': 'boolean'}, 'dangerous_scheme': {'type': 'boolean'}, 'excessive_length': {'type': 'boolean'}, 'cloud_metadata_host': {'type': 'boolean'}, 'suspicious_keywords': {'type': 'boolean'}, 'embedded_credentials': {'type': 'boolean'}, 'excessive_subdomains': {'type': 'boolean'}, 'private_or_local_host': {'type': 'boolean'}, 'unicode_or_punycode_host': {'type': 'boolean'}}, 'additionalProperties': False}, 'domain': {'type': ['string', 'null']}, 'signals': {'type': 'array', 'items': {'type': 'object', 'required': ['code', 'severity', 'score', 'message'], 'properties': {'code': {'type': 'string'}, 'score': {'type': 'number'}, 'message': {'type': 'string'}, 'severity': {'enum': ['info', 'low', 'medium', 'high', 'critical'], 'type': 'string'}}, 'additionalProperties': False}}, 'decision': {'enum': ['allow', 'notice', 'confirm', 'block'], 'type': 'string'}, 'hostname': {'type': ['string', 'null']}, 'protocol': {'type': ['string', 'null']}, 'subdomain': {'type': ['string', 'null']}, 'risk_score': {'type': 'number'}, 'public_suffix': {'type': ['string', 'null']}, 'normalized_url': {'type': ['string', 'null']}, 'policy_applied': {'enum': ['permissive', 'balanced', 'strict'], 'type': 'string'}, 'schema_version': {'type': 'string'}, 'ruleset_version': {'type': 'string'}, 'context_completeness': {'enum': ['full', 'partial', 'none'], 'type': 'string'}}, 'additionalProperties': False}
inspect_command
Analyze a shell command before execution and return a deterministic, policy-aware decision (allow, notice, confirm or block) without running it, under the applicable policy — permissive, balanced or strict, balanced by default. Paths outside a known workspace_root are treated as higher risk than paths inside it.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['command'], 'properties': {'cwd': {'type': 'string', 'maxLength': 4096, 'description': 'Optional working-directory context. It is never accessed.'}, 'shell': {'enum': ['bash', 'sh', 'zsh', 'powershell', 'cmd', 'unknown'], 'type': 'string', 'description': 'The command shell, when known.'}, 'policy': {'enum': ['permissive', 'balanced', 'strict'], 'type': 'string', 'description': 'Optional policy used to compute the decision: permissive, balanced or strict (default: balanced).'}, 'command': {'type': 'string', 'maxLength': 16384, 'minLength': 1, 'description': 'The complete command text to inspect without executing it.'}, 'context': {'type': 'object', 'properties': {'workspace_root': {'type': 'string', 'maxLength': 4096, 'description': 'Optional workspace root. Paths that resolve outside it are treated as higher risk than paths inside it.'}}, 'description': 'Optional declarative context.', 'additionalProperties': False}}, 'additionalProperties': False}
Schéma de sortie
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['valid', 'command', 'shell', 'cwd', 'risk', 'risk_score', 'decision', 'policy_applied', 'ruleset_version', 'schema_version', 'context_completeness', 'signals', 'checks'], 'properties': {'cwd': {'type': ['string', 'null']}, 'risk': {'enum': ['safe', 'low', 'medium', 'high', 'critical'], 'type': 'string'}, 'shell': {'enum': ['bash', 'sh', 'zsh', 'powershell', 'cmd', 'unknown'], 'type': 'string'}, 'valid': {'type': 'boolean'}, 'checks': {'type': 'object', 'required': ['destructive_filesystem', 'root_target', 'privilege_escalation', 'network_access', 'network_download', 'network_transfer', 'remote_code_execution', 'sensitive_file_access', 'possible_exfiltration', 'permission_change', 'persistence_change', 'system_modification', 'obfuscated_execution', 'command_chaining', 'shell_spawning'], 'properties': {'root_target': {'type': 'boolean'}, 'network_access': {'type': 'boolean'}, 'shell_spawning': {'type': 'boolean'}, 'command_chaining': {'type': 'boolean'}, 'network_download': {'type': 'boolean'}, 'network_transfer': {'type': 'boolean'}, 'permission_change': {'type': 'boolean'}, 'persistence_change': {'type': 'boolean'}, 'system_modification': {'type': 'boolean'}, 'obfuscated_execution': {'type': 'boolean'}, 'privilege_escalation': {'type': 'boolean'}, 'possible_exfiltration': {'type': 'boolean'}, 'remote_code_execution': {'type': 'boolean'}, 'sensitive_file_access': {'type': 'boolean'}, 'destructive_filesystem': {'type': 'boolean'}}, 'additionalProperties': False}, 'command': {'type': ['string', 'null']}, 'signals': {'type': 'array', 'items': {'type': 'object', 'required': ['code', 'severity', 'score', 'message'], 'properties': {'code': {'type': 'string'}, 'score': {'type': 'number'}, 'message': {'type': 'string'}, 'severity': {'enum': ['info', 'low', 'medium', 'high', 'critical'], 'type': 'string'}}, 'additionalProperties': False}}, 'decision': {'enum': ['allow', 'notice', 'confirm', 'block'], 'type': 'string'}, 'risk_score': {'type': 'number'}, 'policy_applied': {'enum': ['permissive', 'balanced', 'strict'], 'type': 'string'}, 'schema_version': {'type': 'string'}, 'ruleset_version': {'type': 'string'}, 'context_completeness': {'enum': ['full', 'partial', 'none'], 'type': 'string'}}, 'additionalProperties': False}
inspect_file
Inspect a Base64-encoded file locally for deterministic structural and security risk signals without executing it, and return a policy-aware decision (allow, notice, confirm or block) under the applicable policy — permissive, balanced or strict, balanced by default.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['filename', 'content_base64'], 'properties': {'policy': {'enum': ['permissive', 'balanced', 'strict'], 'type': 'string', 'description': 'Optional policy used to compute the decision: permissive, balanced or strict (default: balanced).'}, 'context': {'type': 'object', 'properties': {'workspace_root': {'type': 'string', 'description': 'Accepted for contract consistency; file inspection has no filesystem paths to scope, so it has no effect here.'}}, 'description': 'Optional declarative context.', 'additionalProperties': False}, 'filename': {'type': 'string', 'minLength': 1, 'description': 'The original filename, including its extension.'}, 'content_base64': {'type': 'string', 'description': 'The complete file content encoded as canonical Base64 (maximum decoded size: 1 MiB).'}}, 'additionalProperties': False}
Schéma de sortie
{'type': 'object', '$schema': 'http://json-schema.org/draft-07/schema#', 'required': ['valid', 'filename', 'detected_type', 'declared_extension', 'size_bytes', 'sha256', 'risk', 'risk_score', 'decision', 'policy_applied', 'ruleset_version', 'schema_version', 'context_completeness', 'signals', 'checks'], 'properties': {'risk': {'enum': ['safe', 'low', 'medium', 'high', 'critical'], 'type': 'string'}, 'valid': {'type': 'boolean'}, 'checks': {'type': 'object', 'required': ['empty_file', 'exceeds_size_limit', 'dangerous_extension', 'double_extension', 'executable_content', 'extension_type_mismatch', 'suspicious_filename'], 'properties': {'empty_file': {'type': 'boolean'}, 'double_extension': {'type': 'boolean'}, 'exceeds_size_limit': {'type': 'boolean'}, 'executable_content': {'type': 'boolean'}, 'dangerous_extension': {'type': 'boolean'}, 'suspicious_filename': {'type': 'boolean'}, 'extension_type_mismatch': {'type': 'boolean'}}, 'additionalProperties': False}, 'sha256': {'type': ['string', 'null']}, 'signals': {'type': 'array', 'items': {'type': 'object', 'required': ['code', 'severity', 'score', 'message'], 'properties': {'code': {'type': 'string'}, 'score': {'type': 'number'}, 'message': {'type': 'string'}, 'severity': {'enum': ['info', 'low', 'medium', 'high', 'critical'], 'type': 'string'}}, 'additionalProperties': False}}, 'decision': {'enum': ['allow', 'notice', 'confirm', 'block'], 'type': 'string'}, 'filename': {'type': ['string', 'null']}, 'risk_score': {'type': 'number'}, 'size_bytes': {'type': ['number', 'null']}, 'detected_type': {'type': ['string', 'null']}, 'policy_applied': {'enum': ['permissive', 'balanced', 'strict'], 'type': 'string'}, 'schema_version': {'type': 'string'}, 'ruleset_version': {'type': 'string'}, 'declared_extension': {'type': ['string', 'null']}, 'context_completeness': {'enum': ['full', 'partial', 'none'], 'type': 'string'}}, 'additionalProperties': False}
Ajouté
analyze_tool_call
17 September 2026 12:42
Ajouté
inspect_file
17 September 2026 12:42
Ajouté
inspect_command
17 September 2026 12:42
Ajouté
analyze_url_risk
17 September 2026 12:42

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…