M06 · Agentic AI · MCP · API governance

Tool synthesis (MCP)

Turn an OpenAPI surface into scope-gated, risk-annotated tools the agent may call.

$ python -m fde_toolkit tools

Workflow

the order an FDE actually runs it in

  1. 1Parse the OpenAPI spec into operations, parameters and response schemas.
  2. 2Classify each operation's risk from method, side effects and data class.
  3. 3Apply denylist and scope filters so unsafe tools never enter the manifest.
  4. 4Emit MCP descriptors with read-only annotations and approval requirements.
  5. 5Log every synthesised call with identity, scope and policy decision.

Function output

deterministic trace

GET  /customers/{id}  -> get_customer      risk LOW   read_only=true   scope customers.read
POST /payments        -> create_payment    risk HIGH  approval=required scope payments.write
DELETE /accounts/{id} -> denylisted        never enters the manifest