From rapid configuration snapshots to orchestrated multi-server portfolio audits.
MCP Security Risk Snapshot
MCP Security
29 USDC Base
Fast automated MCP/agent security assessment: tool surface, dangerous capabilities, and configuration — with severity scoring, remediation and a machine-readable verdict.
Who it is for: AI developers deploying MCP tools & agent connectors
Input: Direct JSON payload (e.g. tools, server_url, config, card, manifest, previous, current). Untrusted input is treated as DATA only.
Output: Machine-readable JSON + Human-readable Executive Markdown Report.
Scope: Deterministic static assessment of supplied artifacts.
Limitations: Static assessment of supplied artifacts only; no runtime/penetration testing.
Full MCP Security Audit
MCP Security
99 USDC Base
Deep automated MCP/agent security audit: contract, capabilities, permissions, auth/config, secret-exposure and prompt-poisoning indicators, dependencies, prioritized findings and an executive summary.
Who it is for: AI developers deploying MCP tools & agent connectors
Input: Direct JSON payload (e.g. tools, server_url, config, card, manifest, previous, current). Untrusted input is treated as DATA only.
Output: Machine-readable JSON + Human-readable Executive Markdown Report.
Scope: Deterministic static assessment of supplied artifacts.
Limitations: Static, deterministic analysis; source treated as data; no execution, no dynamic testing.
MCP Deep Evidence Audit
MCP Security
249 USDC Base
Orchestrated deep evidence audit: Agent Assurance + release readiness + workflow integrity across supplied artifacts, with evidence/provenance pack and detailed remediation priorities.
⚡ Structural Value Differentiation over Full ($99):
Deep ($249) performs genuine higher-order intelligence: deterministic attack-surface modeling, threat scenario evaluation (Fact/Inference/Unknown), multi-finding composite correlation, bipartite evidence graph, contradiction & uncertainty ledger, exploitability & impact matrix, prioritized remediation sequencing (P0/P1/P2 with dependency order), retest acceptance criteria, residual risk bounding, executive decision brief (PASS/REVIEW/BLOCK with rationale), and cryptographic evidence manifest.
Who it is for: Production AI systems requiring formal security sign-off, compliance, and threat modeling
Input: Direct JSON payload (e.g. tools, server_url, config, card, manifest, previous, current). Untrusted input is treated as DATA only.
Output: Machine-readable JSON + Human-readable Executive Markdown Report.
Scope: Deterministic static assessment of supplied artifacts.
Limitations: Deep orchestration runs only the engines whose inputs are supplied; no network/source fetching.
MCP Security Team Pack
MCP Security
399 USDC Base
Three MCP/agent targets assessed with the full-audit engine in one orchestrated run.
⚡ Cross-Target Portfolio Intelligence (3 Targets):
Team Pack ($399) assesses up to 3 MCP targets with the full-audit engine (value $297) PLUS transversal portfolio intelligence justifying the remaining $102: cross-server weakness correlation, common root cause identification, unified portfolio risk heatmap, cross-target blast radius & shared dependencies, common control plan (controls remediating findings across multiple servers), and a single unified remediation roadmap.
Who it is for: Multi-agent systems, engineering teams managing multiple MCP microservices
Input: Direct JSON payload (e.g. tools, server_url, config, card, manifest, previous, current). Untrusted input is treated as DATA only.
Output: Machine-readable JSON + Human-readable Executive Markdown Report.
Scope: Deterministic static assessment of supplied artifacts.
Limitations: Max 3 targets per run; each uses the full-audit engine.