The surface appears read-only from this sample.
mcpServers.readonlyDocs.tools[0]: docs.searchBrowser-local execution surface scanner
Load redacted tool material, inspect the detected surface, then edit fail-closed policy and export local HELM artifacts. Verify receipt stays available as a peer mode.
Paste, upload, or load a sample.
Review detected action categories.
Edit fail-closed decisions.
Download local artifacts.

Intake
Use redacted MCP configs, tool manifests, GitHub app scopes, or sample logs. The pasted text stays in this browser.
Raw pasted material is never attached to the contact request or telemetry. Only derived counts and the generated summary are staged locally after compile.
6 custom or low-confidence actions are visible before export. Unknown write-like tools default to DENY until mapped.
5 actions
The surface appears read-only from this sample.
mcpServers.readonlyDocs.tools[0]: docs.searchThe surface appears read-only from this sample.
mcpServers.readonlyDocs.tools[1]: issues.readThe surface can change source code, pull requests, workflows, or repository state.
mcpServers.github.permissions.contents: writeThe surface can change source code, pull requests, workflows, or repository state.
mcpServers.github.permissions.pull_requests: writeThe surface can change source code, pull requests, workflows, or repository state.
mcpServers.github.permissions.actions: write1 actions
The surface can export, transform, or post customer records or private user data.
mcpServers.slack.tools[0]: chat.postMessage2 actions
The surface can move money, issue refunds, create invoices, or change financial state.
mcpServers.finance.tools[0]: stripe.refund.createThe surface can move money, issue refunds, create invoices, or change financial state.
mcpServers.finance.tools[1]: payments.transfer4 actions
The surface can grant roles, invite users, rotate tokens, or change permission state.
mcpServers.slack.tools[1]: conversations.inviteThe surface can grant roles, invite users, rotate tokens, or change permission state.
mcpServers.github.permissions.contents: writeThe surface can grant roles, invite users, rotate tokens, or change permission state.
mcpServers.github.permissions.pull_requests: writeThe surface can grant roles, invite users, rotate tokens, or change permission state.
mcpServers.github.permissions.actions: writeTop 5 of 10.
The surface can grant roles, invite users, rotate tokens, or change permission state.
mcpServers.slack.tools[1]: conversations.inviteRequire least-privilege scope, owner approval, identity binding, and an access receipt.
The surface can move money, issue refunds, create invoices, or change financial state.
mcpServers.finance.tools[0]: stripe.refund.createRequire spend policy, threshold approval, ledger context, and a finance receipt.
The surface can move money, issue refunds, create invoices, or change financial state.
mcpServers.finance.tools[1]: payments.transferRequire spend policy, threshold approval, ledger context, and a finance receipt.
The surface can change source code, pull requests, workflows, or repository state.
mcpServers.github.permissions.contents: writeRequire repository scope, code-owner approval, policy verdict, and a code/action receipt.
The surface can grant roles, invite users, rotate tokens, or change permission state.
mcpServers.github.permissions.contents: writeRequire least-privilege scope, owner approval, identity binding, and an access receipt.
4 shown
Receipt required - Threshold required
Receipt required - Threshold required
Receipt required - Owner required
Receipt required - Owner required
ALLOW / ESCALATE / DENY
Runtime overlay remains deny by default unless a rule says otherwise.
12 local rules compiled.
10 rules require receipt evidence.
6 custom or low-confidence actions need mapping.
1
All files are generated in this browser.
Review handoff contains the generated summary, categories, decision counts, and custom MCP count only.
Verification remains a peer mode
Use the Verify receipt tab to inspect EvidencePack hashes offline without changing scanner behavior or uploading source material.
Route-local notes
The scanner accepts redacted MCP configs, tool manifests, GitHub scopes, and sample logs. It classifies likely side effects by category, confidence, and sanitized evidence snippets. The raw source remains in the browser and is not attached to telemetry or contact handoff.
Read-only actions can move to Allow. Consequential writes move to Escalate or Deny with receipts and owner approval. Unknown custom MCP tools stay denied until a human maps the action, because absence of a known policy is treated as no authority to execute.
Exports are generated locally as Markdown, JSON, MCP overlay, and HELM kernel policy pack files. The review handoff stores only derived summaries: source type, category counts, decision counts, warning state, and custom MCP count. Pasted or uploaded source text does not leave the page.