Available tools
Owner and Admin can use every tool listed above. Writes need custom guardrails on your plan.
Standard Users can use
analyzePlan only. They can also use getFinding and updateFindingState on development findings from their own Corridor scans. They cannot list, create, edit, restore, or archive guardrails.
Guardrail versioning through MCP
Guardrail versioning is in private beta. Corridor must enable it for your team.
getGuardrailVersions— list version history, newest first. Read-only.restoreGuardrailVersion— copy an earlier version onto the live guardrail. This writes a new current version. History stays.
restoreGuardrailVersion needs custom guardrails on your plan.
Update and archive through MCP
Updating and archiving guardrails through MCP is a separate private beta feature. Corridor must enable it for your team.
updateGuardrail— edit name, overview, or text. Available when versioning is on.archiveGuardrail— archive a guardrail so it stops running. Needs archive enabled as well.
analyzePlan
TheanalyzePlan tool is the core tool that AI coding assistants call before generating code. It takes a description of what you plan to implement and returns relevant security context from your project’s guardrails and context documents. This helps prevent vulnerabilities by giving the AI assistant project-specific security guidance at the point of code generation.
Parameters:
Example:
Example conversation
- “Add a new API endpoint” → calls
analyzePlanfor security context before writing code - “Show me details about finding X” → calls
getFinding - “Mark this finding as a false positive” → calls
updateFindingState - “What guardrails should I follow?” → calls
getGuardrails - “Create a guardrail for SQL injection prevention” → calls
createGuardrail - “Show me this guardrail’s versions” → calls
getGuardrailVersions - “Restore this guardrail to an earlier version” → calls
restoreGuardrailVersion - “Update this guardrail” → calls
updateGuardrail - “Archive this guardrail” → calls
archiveGuardrail
Requirements
- Corridor extension installed and authenticated
- MCP enabled for your team (team setting)
- IDE Extension Support entitlement on your plan
- User must be a member of a team that owns the project
Security notes
- Tools validate team membership before granting access
- Uniform 404 responses prevent information leakage
- Admin operations reject API tokens (require user auth)
Next steps
Findings
Track and remediate security issues
Guardrails
Configure security guardrails