Default-deny tool registry
Servers must be inspected, provenance-checked, permission-approved and explicitly enabled before an agent can use their tools.
Context7 Documentation
discovereddocumentation:read
GitHub MCP
discoveredissues:read, issues:write, pull_requests:read, pull_requests:write, repository:read, rules:read, workflows:read
Playwright Browser MCP
discoveredbrowser:read, browser:test
PostgreSQL Read-only MCP
discovereddatabase:read
Supabase MCP
discovereddocumentation:read, database:read, database:migration, functions:read
anzenforge mcp inspect <id> --tools-file tools.json --digest sha256:... then approve and enable with an explicit permission subset.