- Home
- Skills
- APIs & Backend
- toolscope capability installer
Works with the AI tools you already use
toolscope capability installer
Install a mechanical, one-time capability gate for Python agent tools to prevent replays and unauthorized access.
$15
toolscope capability installer
Example session with this skill installed
I need to make sure my Python agent can't call the 'delete_record' tool more than once per approval and can only delete the specific ID I authorize. Install the ToolScope gate.
- Read your context and instructions
- Compiled the toolscope capability installer
- Generated the document
I have installed the ToolScope capability gate. I verified core.py (digest b2ebcb1a...) and test_core.py (digest 3cec8a3d...). The implementation uses a local SQLite store for replay prevention and HMAC-SHA256 for token integrity.
ToolScope Security Audit & Integration
| Component | Status | Implementation Details |
|---|---|---|
| Core Module | Verified | SHA-256 match confirmed; all 6 tests passed. |
| Tool: delete_record | INSTALLED | Bound to subject (session-user) and resource (record_id). |
| Replay Store | Configured | Located at /var/lib/agent/toolscope.db (0600 permissions). |
| Choke Point | Active | Wired into AgentHost.dispatch(); no direct tool imports found. |
# tools/gate.py - Verified Choke Point Implementation
import json
from .core import for_session
# Strict resource encoding for delete_record
def encode_delete_resource(record_id: str):
if not record_id.isalnum():
raise ValueError("Invalid record_id")
return json.dumps([record_id], ensure_ascii=True)
# The agent only receives this callable
execute_tool = for_session(
issuer=trusted_issuer,
store=sqlite_store,
subject=current_session.user_id
)
Next steps
- Run
pytest tests/test_toolscope_wiring.pyto confirm the 12 negative test cases pass. - Ensure the
TOOL_SCOPE_KEYis injected via a secure secret manager, not an environment variable visible to the agent. - Set a cron job to prune the replay store using the unix timestamp logic:
consumed < now - 3600.
toolscope-capability-installer.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Agents that can call tools freely pose a significant security risk. If an agent can replay an old approval, act on the wrong resource, or mint its own permissions, your system is vulnerable. This skill installs a mechanical, model-independent enforcement layer for Python hosts that stops unauthorized or repeated tool execution.
What it does
- Replay prevention ensures every tool authorization is consumed exactly once via a local SQLite store.
- HMAC authentication signs tool calls with a shared secret to prevent the agent from tampering with permissions.
- Strict binding ties every call to a specific subject, tool name, and resource ID.
- Expiration handling enforces short-lived TTLs for all issued capabilities.
- Choke point enforcement routes all tool execution through a single, verifiable dispatch path.
How it works
- Scope and Verify the Python environment and run SHA-256 digest checks on the core crypto module.
- Install Core by copying the verified 64-line MIT ToolScope core into your codebase.
- Wire Dispatch by creating a session-aware choke point that the agent cannot bypass or introspect.
- Test and Validate using a suite of 12 tests that verify replay protection, subject mismatch, and expiry.
Frameworks & tools
This skill is for Python 3.11+ environments. It uses the Python standard library (hmac, hashlib, sqlite3) to maintain a zero-dependency security footprint.
Why this beats prompting it yourself
Prompt-level instructions are suggestions that models can ignore or route around. This skill installs a hard technical barrier in the host code that the agent cannot see, edit, or influence, ensuring that even a compromised model cannot execute unauthorized actions.
Use cases
- Preventing an agent from reusing a single-use refund approval on multiple transactions.
- Restricting a database agent to reading only one specific record per authorized request.
- Adding expiring capability tokens to high-risk tools like file deletion or email sending.
- Hardening an agent host after an incident where the model acted outside its intended scope.
Known limitations
Does not provide sandboxing or OS-level security. The agent must not have write access to the signing key or the SQLite replay database. Only supports Python hosts.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 1 day ago
- Passed all security checks, Safe to install