aspex_security_impact | drift between the current environment and a proposed .mcp.json (plus optional .claude/settings.json hooks): verdict, blast radius before/after, security-relevant changes, attack paths added and removed. The proposal is analyzed statically and never launched. Existing user-level servers are included so compositions with them are visible. |
aspex_explain | the deterministic answer to a security question (see explain) |
aspex_scan | agents, servers with capabilities and scope, hook and skill counts, blast radius with reasons, attack path counts |
aspex_get_capabilities | every server’s capabilities, roots, scope, egress class, agent-state writes |
aspex_get_attack_paths | AP001-AP006 with evidence, impact, remediation |
aspex_verify | drift against a lockfile (.lock or .json paths only) |