Map declared agent tools to resource scope, data class, role and approval condition, and produce a versioned permission matrix with the list of assumptions the run could not make.
This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.
Run the checked-in example
npm run example # examples/clean, exits 0
node bin/agent-permission-map.mjs --root examples/broad # exits 1
node bin/agent-permission-map.mjs --root examples/incomplete # exits 2Read the result
A list this build could not read is never reported as a list that was empty. A tool whose every scope, data class or role reference was refused raises tool-scopes-unreadable, tool-data-classes-unreadable or tool-roles-unreadable — not the "declares no …" sentence, which asserts an absence about a declaration sitting in the file. For the same reason role-grants-nothing stays silent whenever any grant in tools.json went unread: the reference nobody could read may be the one that granted that role.
Where this check stops
Every limit is enforced and named when it is reached, and exceeding one makes the run incomplete rather than truncating silently. The defaults and their caps are in docs/permission-rules.md.
Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.
Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.