Skip to content

Risk scoring: derive MCP agent power from live tools/list #203

Description

@arunSunnyKVS

Follow-up to the deployment-aware risk scoring feature.

For MCP targets, runAll already connects and calls tools/list before the evaluator loop. Use that live tool surface to derive the Tools / Autonomy factors in deriveAgentProfile() directly (count, write-capability, privilege) instead of relying on businessUseCase text alone.

  • Thread the discovered ToolInfo[] into profile derivation on the MCP path.
  • Keep the text heuristic for agent (HTTP/local-script) targets, which have no introspectable tool list.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions