Exposes selected operations of an existing REST/OpenAPI app as MCP tools with generated schemas, permission annotations, and a risk class, requiring explicit opt-in before anything is listed and a second flag for destructive calls. Enforces security-first guardrails such as environment-injected auth, a single confined base URL, timeouts, response caps, rate limiting, and a local test console for trying tools.
Compiles YAML adapters or OpenAPI specs into a minimal MCP tool surface that exposes only declared capabilities to agents, with risk-tiered execution, human approval queues, credential brokering, prompt-injection sanitising and NIST AU-3 audit logging. This lets operators put scoped identity, permissions and kill switches in front of any API so agents can call exactly the tools they need and nothing more.