Per-agent scoped MCP tool proxy — credential isolation, resource scoping, and audit logging for AI agent deployments