MCPSecurityReady

MCP security diagnostic

Check MCP servers before connecting them to your stack

Inventory, permissions, secrets, prompt injection, tool poisoning, STDIO/SSE and approval policy in one actionable checklist.

A fast control point for teams adopting MCP

MCPSecurityReady helps platform, SecOps and data teams frame risks before installing a local or remote MCP server. The diagnostic runs in the browser and generates a shareable report without collecting answers.

Interactive diagnostic

Select the controls already in place. The score and priorities update locally.

Tool inventory

Owner: Platform
Expected evidence: MCP register, owner, environment, version, source and validation date.

Permissions and least privilege

Owner: IAM
Expected evidence: Role-tool matrix, dedicated service accounts, access reviews.

Secrets and sensitive data

Owner: SecOps
Expected evidence: Vault, rotation, log redaction and leak tests.

Prompt injection and tool poisoning

Owner: AppSec
Expected evidence: Adversarial tests, reviewed tool descriptions, context guardrails.

STDIO, SSE and network transports

Owner: Infrastructure
Expected evidence: Flow diagram, TLS, network filtering and reverse proxy configuration.

Approval policy

Owner: CISO
Expected evidence: Approval rules, audit trail and exception examples.

Minimum controls before production

Sponsored placement
Partner resource
Secure MCP operations guide