# MCP Tool Trust, Permission & Schema Drift Intelligence (`quanmatrix/mcp-tool-trust-permission-schema-drift-intelligence`) Actor

Use this Actor to monitor mcp tool trust, permission and schema drift changes and return decision-ready change signals. Compare MCP tool snapshots for permission expansion, schema drift and poisoning signals, then emit trust scores and ALLOW, REVIEW or BLOCK actions.

- **URL**: https://apify.com/quanmatrix/mcp-tool-trust-permission-schema-drift-intelligence.md
- **Developed by:** [Rafael Barreto Haddad](https://apify.com/quanmatrix) (community)
- **Categories:** Developer tools, Automation
- **Stats:** 2 total users, 1 monthly users, 0.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $11.20 / 1,000 results

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.
Since this Actor supports Apify Store discounts, the price gets lower the higher subscription plan you have.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

## MCP Tool Trust, Permission & Schema Drift Intelligence

Use this Actor to monitor mcp tool trust, permission and schema drift changes and return decision-ready change signals. It is designed for repeatable human, API, Apify AI, and MCP-driven workflows.

Compare MCP tool snapshots for permission expansion, schema drift and poisoning signals, then emit trust scores and ALLOW, REVIEW or BLOCK actions.

### Why use this Actor

Agent teams need continuous evidence when an MCP tool silently changes permissions, arguments, descriptions or destructive behavior after initial approval. This Actor sits above raw extraction: supply a current dataset, optionally add a previous snapshot, and receive an aggregated report built for recurring monitoring and AI-agent workflows.

### Key features

- Combines permission drift, schema drift and tool-description poisoning signals in one baseline model.

- Focuses on before-versus-after trust changes rather than one-time vulnerability scanning.

- Emits deterministic ALLOW, REVIEW and BLOCK decisions for agent workflows.

- Reads inline JSON rows or Apify Dataset IDs with limited READ permission.

- Writes one auditable report to the default Dataset and `INTELLIGENCE_REPORT`.

### Input

Provide `currentItems` directly or select an Apify Dataset with `currentDatasetId`. For change intelligence, add the prior period with `previousItems` or `previousDatasetId`. `maxItems` caps dataset loading. Optional Gen2 fields can provide a previous analysis and user-supplied economic assumptions.

### Output

The Actor writes one decision-ready report to the default Dataset and to `INTELLIGENCE_REPORT` in the key-value store. The report includes counts, ranked signals, baseline evidence, confidence, regression state, an executive decision, recommended action, and the domain-specific portfolio score.

### Example

Use the prefilled example or replace `currentItems` with rows from an upstream Actor. On recurring runs, provide the prior period in `previousItems` or `previousDatasetId`. The Actor normalizes common aliases, compares snapshots, ranks the strongest entity changes and emits `agentAction`.

### Use cases

- MCP governance.
- AI agent security.
- tool allowlist monitoring.
- enterprise agent platforms.

### Pricing

One primary pay-per-event outcome: one decision-ready intelligence report. Base price USD 0.016 before Apify tier discounts. The 256 MB data-first architecture is designed for strong unit economics.

### Limitations

- Analyzes supplied public or appropriately licensed data and does not bypass restricted sources.
- Scores are decision-support signals, not predictions or guarantees.
- Keep stable identifiers across snapshots for best change detection.
- Competitor evidence is refreshed before publication because the Store changes continuously.

### Workflow

`upstream dataset -> current snapshot -> optional previous snapshot -> normalization -> entity aggregation -> change scoring -> ranked signals -> agentAction`.

# Changelog

This Actor's version history is a separate document: https://apify.com/quanmatrix/mcp-tool-trust-permission-schema-drift-intelligence/changelog.md

# Actor input Schema

## `currentItems` (type: `array`):

Current source or normalized rows to analyze.

## `currentDatasetId` (type: `string`):

Optional Apify Dataset ID used when currentItems is not supplied.

## `previousItems` (type: `array`):

Optional previous snapshot rows for period-over-period comparison.

## `previousDatasetId` (type: `string`):

Optional previous Apify Dataset ID used instead of previousItems.

## `maxItems` (type: `integer`):

Maximum records loaded from a Dataset input.

## `previousAnalysis` (type: `object`):

Optional prior Gen2 output used to calculate decision-metric deltas and regression.

## `valuePerImpactUnitUsd` (type: `number`):

Optional user-supplied economic value per impact unit. Leave empty to avoid monetary estimation.

## `monthlyRuns` (type: `integer`):

Optional expected monthly run count used only with valuePerImpactUnitUsd for economic impact estimation.

## `mcpConnectors` (type: `array`):

Optional MCP connectors authorized in your Apify account. Use them to send or write this Actor result to tools such as Slack, Notion, GitHub, Sentry, Supabase, or another compatible MCP service.

## `mcpActionPreset` (type: `string`):

Choose a safe action pattern. AUTO\_SAFE\_WRITE discovers a compatible non-destructive write tool automatically; use a specific preset for Slack, GitHub, Notion, or database delivery.

## `mcpToolName` (type: `string`):

Optional exact MCP tool name. Leave blank to let the selected MCP action preset discover a compatible tool automatically.

## `mcpToolArguments` (type: `object`):

JSON object passed to the selected MCP tool. String values may use {{actor\_title}}, {{result\_summary}}, or {{result\_json}} placeholders.

## `mcpFailOnError` (type: `boolean`):

When enabled, an MCP delivery error fails the Actor run. Disabled by default so data extraction and intelligence results remain available even if the external destination is unavailable.

## Actor input object example

```json
{
  "currentItems": [
    {
      "server": "crm-mcp",
      "tool": "search_contacts",
      "changeType": "permission expansion",
      "scope": "contacts:write",
      "destructive": true,
      "riskScore": 82,
      "observedAt": "2026-09-19"
    },
    {
      "server": "docs-mcp",
      "tool": "search_docs",
      "changeType": "schema drift",
      "scope": "docs:read",
      "destructive": false,
      "riskScore": 35,
      "observedAt": "2026-09-19"
    }
  ],
  "previousItems": [
    {
      "server": "crm-mcp",
      "tool": "search_contacts",
      "changeType": "stable",
      "scope": "contacts:read",
      "destructive": false,
      "riskScore": 20,
      "observedAt": "2026-09-12"
    }
  ],
  "maxItems": 20000,
  "monthlyRuns": 1,
  "mcpActionPreset": "AUTO_SAFE_WRITE",
  "mcpToolName": "",
  "mcpToolArguments": {},
  "mcpFailOnError": false
}
```

# Actor output Schema

## `results` (type: `string`):

Decision-ready intelligence report.

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "currentItems": [
        {
            "server": "crm-mcp",
            "tool": "search_contacts",
            "changeType": "permission expansion",
            "scope": "contacts:write",
            "destructive": true,
            "riskScore": 82,
            "observedAt": "2026-09-19"
        },
        {
            "server": "docs-mcp",
            "tool": "search_docs",
            "changeType": "schema drift",
            "scope": "docs:read",
            "destructive": false,
            "riskScore": 35,
            "observedAt": "2026-09-19"
        }
    ],
    "previousItems": [
        {
            "server": "crm-mcp",
            "tool": "search_contacts",
            "changeType": "stable",
            "scope": "contacts:read",
            "destructive": false,
            "riskScore": 20,
            "observedAt": "2026-09-12"
        }
    ]
};

// Run the Actor and wait for it to finish
const run = await client.actor("quanmatrix/mcp-tool-trust-permission-schema-drift-intelligence").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = {
    "currentItems": [
        {
            "server": "crm-mcp",
            "tool": "search_contacts",
            "changeType": "permission expansion",
            "scope": "contacts:write",
            "destructive": True,
            "riskScore": 82,
            "observedAt": "2026-09-19",
        },
        {
            "server": "docs-mcp",
            "tool": "search_docs",
            "changeType": "schema drift",
            "scope": "docs:read",
            "destructive": False,
            "riskScore": 35,
            "observedAt": "2026-09-19",
        },
    ],
    "previousItems": [{
            "server": "crm-mcp",
            "tool": "search_contacts",
            "changeType": "stable",
            "scope": "contacts:read",
            "destructive": False,
            "riskScore": 20,
            "observedAt": "2026-09-12",
        }],
}

# Run the Actor and wait for it to finish
run = client.actor("quanmatrix/mcp-tool-trust-permission-schema-drift-intelligence").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "currentItems": [
    {
      "server": "crm-mcp",
      "tool": "search_contacts",
      "changeType": "permission expansion",
      "scope": "contacts:write",
      "destructive": true,
      "riskScore": 82,
      "observedAt": "2026-09-19"
    },
    {
      "server": "docs-mcp",
      "tool": "search_docs",
      "changeType": "schema drift",
      "scope": "docs:read",
      "destructive": false,
      "riskScore": 35,
      "observedAt": "2026-09-19"
    }
  ],
  "previousItems": [
    {
      "server": "crm-mcp",
      "tool": "search_contacts",
      "changeType": "stable",
      "scope": "contacts:read",
      "destructive": false,
      "riskScore": 20,
      "observedAt": "2026-09-12"
    }
  ]
}' |
apify call quanmatrix/mcp-tool-trust-permission-schema-drift-intelligence --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,quanmatrix/mcp-tool-trust-permission-schema-drift-intelligence"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/I0BQoryV9ceegdsUE/builds/02Uh3h4Xpqmsyn5eV/openapi.json
