01 / Model layerAGENT & MCP

MCP security review for servers and agent tools.

An MCP security review is a test of MCP server security: a Model Context Protocol server and the agents that use it, checked for tool poisoning, over-broad permissions, weak authentication, credential exposure and unsafe tool output, so an agent cannot be turned against the systems it connects to. We review the servers you build and the third-party servers your agents rely on, against the current specification and the OWASP Top 10 for Agentic Applications.

For teams publishing an MCP server, and for teams whose agents connect to servers they did not write.

Package
AGENT & MCP
Range, excl. VAT
EUR 6,000 to 15,000
Testing days
4 to 10

MANIFEST / FICTION / THIRD-PARTY MCP SERVER04 ROWS READ / 1 FOUNDSAMPLE

TOOL address_lookupAS THE AGENT RECEIVES IT

  1. SERVERVendor-hosted, connected at start-up
  2. SCOPESread:addresses
  3. DESCRIPTIONA line the page never shows.
  4. VERSIONNot pinned

DESCRIPTION CHANGED UPSTREAM / NOT REVIEWED / ASI04

A tool description is text the model reads as guidance, and this one changed on the vendor’s side after it was approved. We inventory every tool definition with its hash and test what the agent does when one changes.

What does an MCP security review cover?

An MCP server is two things at once: a set of tool descriptions that a model reads as guidance, and an API that acts with real credentials. We review both halves, and the agents in between.1

Every row is a category in our test catalogue. Ids link to the framework that defines them.
No.CategoryWhat we checkMapped to
01Agentic supply chain: MCP servers, plugins and tool definitionsWhether tool names, descriptions and schemas can change after you approved them, and whether your agents pin the versions they rely on.
02Prompt injection resistance, direct and indirectWhether instructions hidden in tool descriptions or tool results are followed by the agent as if they came from you.
03Tool and function calls kept within the task's intended scopeWhether each tool does one thing, validates its arguments on the server, and refuses calls outside its purpose.
04Agent identity, delegated credentials and privilege boundariesWhich identity each tool acts as, whether tokens are issued for this server only, and whether one client can act as another.
05API authentication and token handlingAuthentication on every request, token audience and lifetime, and the consent flow when the server sits in front of a third-party API.
06Server side request forgery defensesWhether URLs the server fetches, or hands a client to fetch, can be pointed at internal addresses or cloud metadata.
07Validation of model output before it reaches code, browsers or databasesWhether tool output is checked before it reaches the model, the client’s interface or another system.
08Code execution boundaries and sandboxing for agentsFor servers that run on a user’s machine: what they can execute, with which privileges, and after what consent.
09Secrets in code, images and secret storesWhere the server keeps its own secrets and API keys, and who can read them in code, images and configuration.
10Rate limits and resource consumption controlsRate limits and timeouts on tool invocations, per client and per tool.

Out of scope Third-party MCP servers you do not operate are reviewed from your side of the connection, through your integration, unless their operator gives written permission for more.

What does an MCP finding look like?

One card per finding, with the same fields every time. This one comes from the fictional engagement in our sample report.

SAMPLE / FICTIONAL CLIENT / REAL FORMAT

SAMPLE-01 / F-05

MEDIUMCVSS-B 5.9MODEL LAYERASI04

A third-party MCP server’s tool descriptions are trusted as written

Business impact
The assistant’s behaviour depends on a vendor’s text that nobody on the client’s side reviews.
Evidence
CONFIGURATION REVIEW, APPENDIX C Found by review, not by an attempt, so there is no rate to report.
CVSS v4.0 vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Fix principle
Pin third-party tool definitions to a reviewed version, and alert when the vendor’s version changes.
Retest
FIXED 2026-09-24 Definitions pinned; a change now raises an alert.
The format every finding takes in our report. The client and the finding are fiction; the fields are not. Read F-05 in the sample report.

How does an MCP security review run?

Half of it is reading, half is testing. The reading decides where the testing goes.

  1. 01Read the definitions

    We read every tool the way the model will.

    Names, descriptions, input and output schemas and annotations, for every tool and every version you run. The specification tells clients to treat tool annotations as untrusted unless the server is trusted, so we check where your agents draw that line, and what crosses it.2

  2. 02Authorization

    We test who the server believes you are.

    Token audience and lifetime, scopes, consent and redirect handling when the server proxies a third-party API, and whether holding a session or state handle is treated as proof of identity. The specification forbids passing a client’s token straight through to a downstream API; we check that it does not happen.3

  3. 03Exercise the tools

    We call every tool with what a careless or hostile client could send.

    Server-side validation, access control per tool, rate limits, timeouts and output sanitization, which the specification lists as obligations of every server. Calls run against test data named in the rules of engagement, never against your customers’ records.4

  4. 04Through the agent

    We test the server through the agents that use it.

    A description that looks harmless in review can still steer an agent. We connect a test agent, observe how it chooses and calls tools, and record which descriptions or results change its behaviour, with a reproduction rate and the server version.

  5. 05Supply chain

    We check how definitions reach your agents.

    Who can publish a new version, whether agents re-approve a tool whose definition changed, and whether a server installed on a user’s machine runs with more privilege than its tools need. The answer to the first question decides how far everything else can reach.

What does an MCP security review cost?

An MCP review is priced as our Agent & MCP package, excluding VAT, the same offer as AI agent security testing. One server with a handful of read-only tools sits near the low end of the range.

01 / AI Pentest

AGENT & MCP

EUR 6,000 to 15,000

TYPICALLY 4 TO 10 TESTING DAYS

What moves the price

  • Servers in scope, and how many tools each one exposes
  • Whether the server proxies a third-party API with OAuth
  • Servers on users’ machines, remote servers, or both
  • How many agents and clients connect to it

See all prices

Report
Scope, method, dates, findings with evidence, severity in CVSS v4.0, framework ids, fix guidance and retest status.
Attestation letter
One page that confirms scope, dates and retest status, for customers who need the result without the findings.
Coverage matrix
Every category in scope marked tested, not applicable or out of scope, so the gaps are written down too.
Evidence
An inventory of every tool definition, with the version and hash we reviewed.

Questions about MCP security reviews.

What is an MCP server security review?

An MCP security review tests a Model Context Protocol server and the agents that use it for tool poisoning, over-broad permissions, weak authentication, credential exposure and unsafe tool output. We read every tool definition the way a model would, test the server as an API, and then test it through an agent.

Can you review an MCP server we did not build?

Yes, from your side of the connection. We review its tool definitions, the permissions you grant it and how your agents treat its output, and we test your integration with it. Testing the server’s own infrastructure needs its operator’s written permission, which we can request together with you when it matters.

What do you need from us for an MCP review?

Access to the server and its tool definitions, test credentials for each client role, and a description of the APIs it calls downstream. Source code is optional but shortens the review. For servers that run on users’ machines we also need the install path your users follow, because that is part of what we test.

Is a review of the tool definitions enough?

No. Definitions show intent, not behaviour. A server can skip input validation, pass tokens through, or return output that steers an agent, and none of that is visible in a description. We read the definitions first, then test the running server and the agents that use it.

What does an MCP security review cost?

An MCP review is priced as our Agent & MCP package: EUR 6,000 to 15,000, excluding VAT, typically 4 to 10 testing days. One server with a handful of read-only tools sits near the low end; several servers, OAuth proxying to third-party APIs, and tools that write or spend move it up.

The engagement, in short.

4 to 10 testing days on staging where we can, under the rules of engagement you sign first. Then the report and a one-page letter, and the retest once you have fixed. Every step, from the scoping call to the regression pack, is in the method.