tool-scout

Scores seven dimensions of MCP servers or external tools and generates a scout report with verdict and constraints for adoption decisions.

Updated Apr 21, 2026
One-click install
npx skills add https://github.com/brucebanner010198-commits/DevSecOps-Agency --skill tool-scout-brucebanner010198-commits
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: tool-scout
Source: https://github.com/brucebanner010198-commits/DevSecOps-Agency/tree/main/skills/tool-scout
Command: npx skills add https://github.com/brucebanner010198-commits/DevSecOps-Agency --skill tool-scout-brucebanner010198-commits

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Vet new MCP servers or external tools before adoption to ensure governance, risk controls, and quality entry into production by producing a formal scout report.

Core Features & Use Cases

  • 7-dimension rubric scoring (provenance, scope, abuse-surface, reversibility, secret-handling, maintenance, integration-cost) with a green/yellow/red verdict.
  • Constraint-set generation to bound tool usage and guide ADRs for adoption decisions.
  • On-demand re-scouts for drift, incidents, and quarterly portfolio hygiene reviews.

Quick Start

Run tool-scout on a requested MCP server or external tool to generate a scout report prior to adoption.

Frequently Asked Questions about tool-scout

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I vet an MCP server or external tool before production adoption?

Vetting an MCP server before adoption involves scoring seven dimensions—provenance, scope, abuse-surface, reversibility, secret-handling, maintenance, and integration-cost—to produce a formal scout report with a green, yellow, or red verdict.

What is a tool scout report and how does it guide adoption decisions?

A tool scout report scores external tools across seven risk dimensions and provides a green, yellow, or red verdict alongside a constraint set to bound tool usage and guide architecture decision records for adoption.

How do I assess external tool risk for quarterly portfolio hygiene reviews?

Assessing external tool risk during quarterly portfolio hygiene reviews requires running on-demand re-scouts to evaluate drift, check incident history, and maintain tool hygiene using the seven-dimension scoring rubric.

Can I generate a constraint set to bound MCP server usage in production?

Yes, generating a constraint set to bound MCP server usage in production requires applying the seven-dimension rubric, which outputs constraints that guide ADRs and limit tool scope, secret-handling, and abuse-surface exposure.

What dimensions should I evaluate to ensure governance and risk controls for new tools?

To ensure governance and risk controls for new tools, evaluate provenance, scope, abuse-surface, reversibility, secret-handling, maintenance, and integration-cost to determine if the tool meets quality entry criteria for production.