Large Language Model (LLM) agents struggle to scale safely when exposed to extensive enterprise toolsets. Granting access to every internal tool inflates context windows, degrades tool selection, and creates governance gaps because policies expressed only in prompts are probabilistic advice rather than hard constraints. Existing mitigations such as multi‑agent domain delegation merely decentralize audit logs and cannot guarantee policy compliance across sessions.
We introduce skilder, a framework that packages capabilities into roles—bundles of skills, tools, instructions, and their limiting parameters. An agent starts with a minimal role catalog, discovers the roles required for a task, and receives each role’s assets through a single MCP server. Since tools become reachable only inside learned skills, the server can enforce the learned scope deterministically.
We evaluated skilder against flat‑context tool selection and multi‑agent orchestration on 13 tasks using six models (10 runs each). The simulated authorization layer enforced governance boundaries: no unauthorized tool call or parameter violation (e.g., spending‑limit breach) occurred. Aggregate pass rates indicate whether a model followed the discovery protocol and met response‑quality checks; misses are not authorization failures.
Moreover, by allowing agents to acquire cross‑role capabilities dynamically during a task, skilder preserves problem‑solving flexibility while providing hard system‑level enforcement.
Review: skilder elevates governance from vague prompt‑based advice to verifiable hard constraints through role‑scoped capability delivery, offering a robust security layer without sacrificing agent adaptability.