EnterpriseRBACLeastPrivilegePolicySynthesizer
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@EnterpriseRBACLeastPrivilegePolicySynthesizeraudit this wildcard policy and synthesize a least-privilege version"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
genpark-enterprise-rbac-least-privilege-policy-synthesizer-skill
Enterprise Agentic RBAC/ABAC Least-Privilege Policy Synthesizer & Blast-Radius Auditor. Analyzes historical agent tool call audit logs, detects over-permissioned wildcards (*), synthesizes strict least-privilege JSON security boundary policies, and quantifies attack surface reduction.
🌟 Key Features
100% Zero External Dependencies: Runs entirely on the Python 3.9+ standard library.
Model Context Protocol (MCP) Standard: Native support for JSON-RPC 2.0
initialize,tools/list, andtools/call.Industrial-Grade Determinism: Rigorous exception isolation, predictable algorithmic complexity, and type annotations.
Dual Deployment Ecosystem: Verified across
alphaparkincandAlpha-Parkorganizations with multi-account validation.
Related MCP server: Aegis
🚀 Quick Start
1. Direct Python SDK Usage
"""Example usage for EnterpriseRBACLeastPrivilegePolicySynthesizer."""
import sys
import json
from client import EnterpriseRBACLeastPrivilegePolicySynthesizer
sys.stdout.reconfigure(encoding='utf-8')
def main():
print("=== Enterprise Agent Least-Privilege IAM Policy Synthesizer Demo ===")
synthesizer = EnterpriseRBACLeastPrivilegePolicySynthesizer()
execution_history = [
{"action": "docs:read_sheet", "resource": "docs.tencent.com/sheet/001", "status": "SUCCESS"},
{"action": "docs:write_cells", "resource": "docs.tencent.com/sheet/001", "status": "SUCCESS"},
{"action": "wechat_work:send_msg", "resource": "work.weixin.qq.com/bot/finance", "status": "SUCCESS"},
{"action": "cloud:restart_server", "resource": "tencentcloud:cvm/*", "status": "FAILED"} # failed unauth
]
# 1. Synthesize minimal least-privilege policy from legitimate operations
print("\n--- 1. Synthesizing Scoped Least-Privilege IAM Policy ---")
synth_policy = synthesizer.synthesize_least_privilege_policy("workbuddy_finance_bot", execution_history)
print(json.dumps(synth_policy, indent=2))
# 2. Audit blast radius reduction against over-permissioned wildcard policy
print("\n--- 2. Auditing Attack Surface & Blast Radius Reduction ---")
legacy_wildcard_policy = {
"policy_id": "LEGACY-ADMIN-WILDCARD",
"statements": [{"effect": "ALLOW", "actions": ["*"], "resource": "*"}]
}
audit = synthesizer.audit_policy_blast_radius(legacy_wildcard_policy, synth_policy)
print(f"Wildcard Vulnerability Eliminated: {audit['has_wildcard_vulnerability']}")
print(f"Blast Radius Score: {audit['baseline_blast_radius_score']} -> {audit['least_privilege_blast_radius_score']}")
print(f"Total Attack Surface Reduction: {audit['attack_surface_reduction_pct']}%")
# 3. Validate unauthorized privilege escalation attempt
print("\n--- 3. Verifying Policy Guardrail Against Privilege Escalation ---")
chk_allowed = synthesizer.validate_action_against_policy(synth_policy, "docs:read_sheet", "docs.tencent.com/sheet/001")
print(f"Action 'docs:read_sheet': Allowed = {chk_allowed['allowed']}")
chk_denied = synthesizer.validate_action_against_policy(synth_policy, "cloud:terminate_instance", "tencentcloud:cvm/*")
print(f"Action 'cloud:terminate_instance': Allowed = {chk_denied['allowed']} ({chk_denied['reason']})")
if __name__ == "__main__":
main()
2. Run as Model Context Protocol (MCP) Server
Start standard JSON-RPC 2.0 server over stdio:
python mcp_server.pyExecute embedded test harness:
python mcp_server.py --test🛠️ MCP Tool Specification
Inspect skill.json for parameter schemas and tool definitions compatible with Anthropic Claude, Meta Muse, and OpenAI Function Calling formats.
📜 License
Licensed under the MIT License. Copyright © 2026 GenPark AI.
This server cannot be deployed
Maintenance
Related MCP Connectors
See, price, and control every tool call your AI agents make: policy checks, cost, and audit tools.
Security gateway for AI agents: policy, approval, and audited execution, no secrets shared.
Zero-trust gateway for AI agents: score tool calls, verify agent cards, enforce policy, audit.
Fail-closed policy guardrails for AI agents running kubectl, terraform, helm, and argocd.
Related MCP Servers
- AlicenseAqualityBmaintenanceLocal zero-trust permission gateway for AI agents. Enforces policy-based tool authorization, human approvals, scoped permissions, and cryptographically verifiable audit logs.439 PyPI5Apache 2.0
- FlicenseAqualityBmaintenanceA blast-radius auditor for AI agents that computes combined effective permissions across all connected MCP tools, detects dangerous capability combinations deterministically, and provides a live risk graph and one-click policy fixes.4-
- AlicenseNot gradedqualityCmaintenanceProvides permission gates and tamper-evident audit logging for AI agent tool executions, with declarative policies, consent ladders, and hash-chained verification.MIT
- AlicenseAqualityAmaintenanceLeast-privilege compiler and MCP gateway for AI agents: run your agent in record-only mode, compile the smallest policy it actually needs from its real tool calls, enforce it at the gateway (deny > approve > allow), and keep a SHA-256 hash-chained audit of every call that verifies offline.14169 npm1Apache 2.0