Look twice.Find the gem.

AI agents and MCP servers, each published with its source and what the checks found.

Marketplace

  • Everything
  • AI agents
  • Apps
  • MCP servers
  • Templates
  • What people want
  • What changed this week
  • The verification standard
  • The ooruby Index
  • Servers that publish no source
  • Reliability guides
  • What the catalogue holds
  • Sell here

Our library

  • Everything, in one place
  • Guides
  • Glossary
  • Calculators
  • Checklists and cheat sheets
  • Community

ooruby

  • Home
  • For teams
  • Site status
  • Company projects
  • RSS feed

Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.

Rubricv1.0
AI agentsAppsMCP serversTemplatesWantedCommunityOur library
Sign inSell
Before you buy
All guides
Before you buyBeginner· 6 min read

Permissions worth refusing

The one thing to remember

Grant the narrowest thing that makes the job possible, and prefer a listing that asked for less.

The question

Look at a permission list and know which entries to push back on before you install anything.

Figure

How Permissions worth refusing works, in one picture

1Write access when the job is reading2Open ended command execution3Unbounded outbound network access4Credentials that are not scoped to the task

The same argument as the text, as a chain. Each step is what makes the next one possible.

  1. 1

    Write access when the job is reading

    A tool that summarises, searches, analyses or reports does not need to write. If it asks, the usual reason is that the maker built one broad integration rather than two narrow ones.

    That is a convenience decision by somebody who is not carrying your risk. Prefer the listing that split them.

  2. 2

    Open ended command execution

    There is a real difference between a server that runs a fixed set of named commands and one that will run whatever string it is given. The first has a list you can read. The second has a list that depends entirely on what the model decides to say.

    Our scan distinguishes them, and the listing says which it is. Treat open ended execution as something you grant deliberately, in an environment you would not mind losing.

    This is the single highest consequence permission on the site. Nothing else is close.

  3. 3

    Unbounded outbound network access

    A listing that declares which hosts it may contact can be checked. One that may contact anything cannot, and that is also the shape of the SSRF weakness that a large 2026 scan found in more than a third of URL-accepting MCP servers.

    Prefer a declared egress list. Where there is not one, assume anything the software reads could leave.

  4. 4

    Credentials that are not scoped to the task

    Where a listing needs a key, give it one issued for this purpose with the narrowest scope that works, and rotate it if you stop using the listing.

    Never hand over a personal token that has your own full access attached. If the maker's setup instructions ask for one, that is worth an email before it is worth an install.

You have got it when

You have looked at a listing you were considering and identified at least one permission you would ask about.

Read next

Before you buy
How to judge an agent in ten minutes
How verification works
How to read a findings report without panicking
Running it safely
The first week with a new agent
Before you buy
Should you build it or buy it?
How verification works
Why a badge expires, and what happens when a maker ships
Running it safely
Work out the blast radius before you grant a scope
The bottom line

Grant the narrowest thing that makes the job possible, and prefer a listing that asked for less.

See the AI and semiconductor names

The near-monopolies and the commodities, side by side, because they look identical from outside and they are not.