Agent builders
See which documented actions become potential agent tools.
Capability Mapper · MAP
Capability Mapper translates each documented OpenAPI operation into deterministic capability metadata: access type, risk tags, authentication state, permission alternatives, and sensitive-data context.
The mapper reuses the canonical OpenAPI operation surface. One capability represents one documented path and HTTP method.
Paths, methods, security requirements
Deterministic static classification
Terminal + JSON
This example shows the shape of output, not customer data or runtime proof.
Use the inventory during agent tool design, AppSec review, API contract review, or as the foundation for Readiness.
See which documented actions become potential agent tools.
Review destructive, privileged, financial, object-access, and sensitive-data tags.
Find missing or unclear security metadata in the contract surface.
Static scope
Documented permission alternatives are descriptive metadata. Capability Mapper does not prove the agent can reach an operation or that the server enforces the declared authorization.
Read the technical trust model →Capability Mapper is a one-time Agent Security purchase with the capability_mapper entitlement.