ToolCabana

Agent tools / Authorization and action governance

Preview a proposed policy decision

Evaluate a caller-supplied tool/domain allowlist. Advisory only; this cannot grant a capability or override gateway authorization.

Status: implemented. Runtime: browser-or-local. Version: 1.0.0.

Policies and approvals come from a trusted control plane. Bind decisions to identity, action digest, resource, expiry and nonce.

Supported profile

This tool accepts the schema below. Its result includes data and versioned runtime metadata. Read warnings in returned data for algorithm coverage and assumptions.

Input schema
{
  "type": "object",
  "properties": {
    "action": {
      "type": "object",
      "maxProperties": 2000
    },
    "allowedTools": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    },
    "allowedDomains": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "action",
    "allowedTools"
  ],
  "additionalProperties": false
}
Output schema
{
  "$schema": "http://json-schema.org/draft-07/schema#",
  "type": "object",
  "properties": {
    "data": {
      "type": "object",
      "properties": {
        "verdict": {
          "type": "string",
          "enum": [
            "allow",
            "deny"
          ]
        },
        "warning": {
          "type": "string",
          "maxLength": 200000
        }
      },
      "required": [
        "verdict",
        "warning"
      ],
      "additionalProperties": false,
      "maxProperties": 2000
    },
    "metadata": {
      "type": "object",
      "properties": {
        "tool": {
          "const": "policy.evaluate"
        },
        "version": {
          "const": "1.0.0"
        },
        "runtime": {
          "type": "string",
          "enum": [
            "local",
            "browser",
            "server"
          ]
        },
        "elapsedMs": {
          "type": "integer",
          "minimum": 0,
          "maximum": 9007199254740991
        },
        "retained": {
          "const": false
        }
      },
      "required": [
        "tool",
        "version",
        "runtime",
        "retained"
      ],
      "additionalProperties": false,
      "maxProperties": 2000
    }
  },
  "required": [
    "data",
    "metadata"
  ],
  "additionalProperties": false,
  "$defs": {
    "json": {
      "anyOf": [
        {
          "type": "null"
        },
        {
          "type": "boolean"
        },
        {
          "type": "number"
        },
        {
          "type": "string",
          "maxLength": 200000
        },
        {
          "type": "array",
          "items": {
            "$ref": "#/$defs/json"
          },
          "maxItems": 2000
        },
        {
          "type": "object",
          "maxProperties": 2000,
          "additionalProperties": {
            "$ref": "#/$defs/json"
          }
        }
      ]
    }
  }
}

Example arguments

{
  "action": {
    "tool": "json.parse"
  },
  "allowedTools": [
    "json.parse"
  ]
}

Local MCP tool name: policy__evaluate. Browser and local execution work without a key.

Hosted REST and MCP execution are disabled in this release. Run the example in the browser console below, or use the local MCP server from this repository.

Privacy and limits

256 KiB arguments, 512 KiB output, 20 nesting levels and 2,000 array entries. No input/output logging in this layer. Browser/local utilities do not submit inputs remotely. Optional network operations disclose destination requests. Caller-supplied policies and guardrail findings never grant execution privileges.

136 matching tools

Preview a proposed policy decision

Evaluate a caller-supplied tool/domain allowlist. Advisory only; this cannot grant a capability or override gateway authorization.

Policies and approvals come from a trusted control plane. Bind decisions to identity, action digest, resource, expiry and nonce.

Contract and limitations

Result

Run a tool to see its structured result.

Let a browser agent use this console

Enable WebMCP when your browser supports it. Inputs run locally and results remain visible here.

Full integration guide