WORKBENCH INSTRUMENT · MAP
AI Tool Capability & Permission Analysis
Understand what each tool can do—and what it can change.
Analyze MCP servers, OpenAPI specifications, agent tools, workflow actions, and callable capabilities to identify authentication requirements, permissions, side effects, trust-boundary crossings, approval needs, destructive operations, and excessive scope before launch.
Discover
Inventory callable capabilities from MCP, OpenAPI, agent frameworks, plugins, workflow systems, and custom tool schemas.
Classify
Classify authentication, read, write, delete, send, execute, administer, browser, filesystem, secret, network, and external-effect capabilities.
Identify control gaps
Find excessive scope, missing approvals, destructive operations, risky side effects, inherited permissions, and cross-boundary capabilities.
Hand off
Contribute normalized tool context and findings to Threat Canvas, Authority Graph, Agent Permission Analysis, Agent Authority Review, and release decisions.
Core capabilities
What Tool Analyzer does.
Tool Inventory
Build an inventory of callable tools, operations, workflow actions, MCP servers, API capabilities, and agent-accessible integrations.
Capability Classification
Classify each operation by the data it can access, the action it can perform, the identity it uses, the side effects it can cause, and whether the action is reversible.
Authentication and permission model
Map credentials, API grants, inherited scopes, runtime identities, argument controls, permission boundaries, and side effects before deployment.
Trust Boundary Mapping
Identify operations that cross trust, tenant, identity, data, network, or external-effect boundaries and determine where approvals or stronger controls are required.
Connected analysis handoff
Produce structured tool capsules and findings that contribute to Threat Canvas, Authority Graph, Agent Permission Analysis, Agent Authority Review, and Attack Path Analysis.
Static Analysis First
Analyze definitions, schemas, and approved implementation evidence without invoking production tools, changing customer systems, or claiming observed runtime behavior.
Evidence & signals
What you get out of the box.
Security Model
- Tool inventory
- Tool capsules
- Capability classification
- Authentication and permission model
- Side-effect map
- Trust-boundary crossings
- Approval requirements
- Evidence references
Deliverables
- Threat Canvas inputs
- Authority Graph inputs
- Permission findings
- Control recommendations
- Release-review signals
- Engineering backlog
What it produces
Structured tool context for modeling, review, and hardening.
A tool capsule is the normalized Workbench representation of a callable tool’s schema, authentication, permissions, side effects, boundaries, and evidence references.
AI SECURITY WORKBENCH
Ready to make callable tool authority reviewable?
Use Tool Analyzer to inventory callable capabilities, normalize their authority and side effects, and carry that context into Threat Canvas, Authority Graph, hardening, and release review.
Continue through the Workbench
Continue through the Workbench
Threat Canvas
Place tools, authentication, data movement, and trust-boundary crossings in the system model.
Continue through the Workbench
Authority Graph
Analyze how tools compose with identities, agents, credentials, approvals, and downstream actions.
Continue through the Workbench
Agent Permission Analysis
Apply deterministic security rules to agent and tool configurations.
Continue through the Workbench
Agent Authority Review
Compare intended authority with effective capability and produce a hardening plan.