Archived Scout brief
Archived notes from the Scout validation phase.
This page is retained as background. The current Orisan homepage and public story lead with mcpscan, the local-first MCP server security scanner.
The hypothesis
Approval without repo-local evidence is becoming the gap.
Security teams already know how to review code, dependencies, secrets, and infrastructure. What is newer is the agent layer: local tool access, MCP config, inherited instructions, and repository-specific behavior that may authorize reading, execution, or changes before anyone has written a new line of code.
Validation questions
These notes are not the current launch checklist.
When developers use AI coding tools, do reviewers know what those tools can access in a repo?
Are MCP servers or repo-level agent instruction files reviewed by security today?
Would a local report on READ / EXECUTE / CHANGE authority be useful, or do existing controls already cover it?
How are agent approval decisions documented today?
Would we send the report to an AppSec engineer without explaining it live?
Real-run protocol
The current path is mcpscan validation.
Current project
mcpscan
Release
v0.1.0-alpha.2
Install path
source/editable install only
Boundary
Scout notes are archived background, not the active product story.
Do not use this archived Scout brief as the current product runbook.
Signals
Success looks like pull.
Failure is useful too.
Alpha path