MCP security audit

A fixed-scope MCP audit before agents touch real systems.

MCPScan helps teams review MCP servers, exposed tools, auth signals, token handling, prompt-injection risk, tool poisoning risk, and production-readiness evidence before customer pilots or internal rollout.

Why teams buy this review

Agent authority is hard to see

MCP servers can connect agents to code, databases, SaaS tools, files, cloud actions, and customer data. Teams need a readable inventory of what can execute, retrieve, mutate, or expose data.

Free scanners need triage

Open-source scanners help find signals. The paid audit adds manual context, business impact, remediation priority, and a buyer-safe report your team can share.

Security reviewers need proof

AppSec, AI governance, and customer security teams need evidence around approvals, permissions, secrets, tool descriptions, logging, and safe intake boundaries.

What the audit covers

AreaWhat gets reviewedBuyer outcome
InventoryMCP servers, exposed tools, clients, configs, and environment scope.Know what exists and what is in scope.
PermissionsRead, write, delete, send, deploy, payment, file, database, and network capabilities.Know which tools carry operational risk.
Auth and tokensAuthentication hints, token handling, environment variables, OAuth scopes, and approval boundaries.Reduce credential and scope exposure.
Tool poisoningTool names, descriptions, prompt-facing copy, shadow tools, and metadata that could steer agent behavior.Find risky tool semantics before rollout.
Input and outputSSRF, command injection, path traversal, SQL injection, sensitive data, excessive data, and error disclosure patterns.Prioritize fixes that affect real exposure.
GovernanceAllowlist fit, registry fit, gateway readiness, audit evidence, remediation backlog, and rescan terms.Create a decision packet for launch or review.

Deliverables

Audit report

  • Executive summary.
  • MCP server and tool inventory.
  • Risk-ranked findings with evidence.
  • Business impact and remediation guidance.
  • Buyer-safe summary for internal or customer review.

Remediation path

  • Prioritized fix list.
  • Owner suggestions.
  • Out-of-scope notes.
  • Findings call for qualifying packages.
  • One re-scan for qualifying packages.

Fixed-scope packages

MCP Quick Audit

For one small setup that needs a fast readiness readout.

$750fixed scope
  • Up to 3 MCP servers.
  • 1 environment.
  • Written report.
  • 3 business days after complete intake.
Purchase Quick Audit

MCP Launch Audit

Default first-revenue offer for teams preparing pilots, demos, or security review.

$1,500fixed scope
  • Up to 8 MCP servers.
  • 2 environments.
  • Report and findings call.
  • 1 re-scan after fixes.
Purchase Launch Audit

Enterprise Readiness

For a deeper review before broader rollout or enterprise diligence.

$3,500fixed scope
  • Up to 15 MCP servers.
  • 3 environments.
  • Executive summary.
  • Findings call and 1 re-scan.
Purchase Enterprise Audit

Scope boundaries

Good fit

  • AI agent teams connecting tools to real systems.
  • Devtool teams shipping public MCP servers.
  • AppSec teams approving MCP use.
  • B2B SaaS teams preparing customer security review.

Not a fit

  • Requests for formal compliance certification.
  • Broad penetration testing outside the MCP scope.
  • Unowned systems or materials without authorization.
  • Secret sharing through public issues or public email.