Orisan

Archived Scout brief

Archived notes from the Scout validation phase.

This page is retained as background. The current Orisan homepage and public story lead with mcpscan, the local-first MCP server security scanner.

The hypothesis

Approval without repo-local evidence is becoming the gap.

Security teams already know how to review code, dependencies, secrets, and infrastructure. What is newer is the agent layer: local tool access, MCP config, inherited instructions, and repository-specific behavior that may authorize reading, execution, or changes before anyone has written a new line of code.

Validation questions

These notes are not the current launch checklist.

01

When developers use AI coding tools, do reviewers know what those tools can access in a repo?

02

Are MCP servers or repo-level agent instruction files reviewed by security today?

03

Would a local report on READ / EXECUTE / CHANGE authority be useful, or do existing controls already cover it?

04

How are agent approval decisions documented today?

05

Would we send the report to an AppSec engineer without explaining it live?

Real-run protocol

The current path is mcpscan validation.

Current project

mcpscan

Release

v0.1.0-alpha.2

Install path

source/editable install only

Boundary

Scout notes are archived background, not the active product story.

Do not use this archived Scout brief as the current product runbook.

Signals

Success looks like pull.

Install works without explaining Go modules
Scout runs cleanly on Orisan repos and test fixtures
Markdown and JSON can be inspected without source upload
The report feels clear enough to send without a live walkthrough

Failure is useful too.

Interesting, but not urgent
Existing controls already cover this
AppSec does not own this approval moment
Findings are too obvious or too noisy
The report is not actionable enough to create a ticket, approval note, or policy exception

Alpha path

Use mcpscan release notes for the current alpha.