product image

MCP Launch Readiness Audit — Scan, Fix & Prove Your MCP Server Is Ready to Ship

$79

A complete pre-launch audit system for MCP servers. Tool descriptions are plaintext the connected AI reads as instructions — a poisoned description can override safety rules, hide steps, or exfiltrate data. MCP servers ship with no auth by default. Scan, fix, prove.

GET: mcp-sec-audit scanner — 48 rules across 6 categories (tool poisoning, hardcoded credentials, server exposure, over-privileged tools, SSRF, missing auth/hardening). Python 3.8+, zero deps. Text/JSON/markdown; exits non-zero on HIGH so CI gates. Node wrapper. A concrete fix for every finding. Two hardened templates (Python + TypeScript): bearer auth, per-tool scopes, rate limits, tenant isolation, input validation, output sanitization, audit log. Reliability harness (malformed inputs, bursts; reports crashes/hangs/leaks). Deployment verifier + attestations. GitHub Actions CI. 30-injection regression suite. Branded PDF report generator.

SCOPE: reduces risk — not a certification, security guarantee, or pentest. Checks catch known patterns; can’t prove absence of vulns. Review with a qualified engineer before handling sensitive data.

LICENSE: Perpetual single-seat commercial license. No redistribution/resale/sublicensing/sharing. 7-day refund available if the product is materially not as described or cannot be made functional after reasonable support. Change-of-mind refunds are not available after download or access.

Support: kyler.simmons.partners@gmail.com — Payload. One-time $79. Yours forever.