MCP server security audit
Before you announce your MCP server, get an outside read of what an attacker, or a merely confused agent, can do with it. You get a written, severity-ranked report with concrete fixes, mapped to the OWASP MCP Top 10.
See a real sample report → — the same audit run on our own endpoint, so you know exactly what you get.
Not ready to buy? Run the free self-check first → — the 14 checks we run, published so you can fix the obvious ones yourself.
What we check
Transport & TLS
Certificate chain, protocol versions, HTTP security headers, Streamable HTTP / SSE behaviour, origin handling.
Auth & sessions
Whether unauthenticated clients can list or call tools, token handling, session-id predictability, OAuth metadata if you use it.
Tool surface
Every tool description read as an attacker would: hidden instructions, over-broad scopes, tools that shell out, write, or reach the network.
Injection & poisoning
Prompt-injection paths through tool results and resources, argument validation, path traversal and SSRF in URL-taking tools.
Secrets & data
Keys or internal hostnames leaking through errors, resources, logs, or tool output; what a caller learns about your backend.
Abuse paths
Rate limits, cost amplification (expensive tools with no cap), denial-of-wallet on paid backends, error handling under malformed input.
This is an external, black-box read of a remote MCP endpoint you own or are authorised to test. We do not need your source code; if you want configuration or code reviewed as well, paste it in the intake and it is covered by the same price. It is a professional review, not a certification or a penetration-test attestation.
What you get
- A written report at a private-by-obscurity URL
golemreach.com/reports/<first 10 hex of your tx>/, within 72 hours of verification. Ask in the intake and we deliver by email instead of publishing. - Each finding with severity, evidence (the exact request and response), and a fix you can hand to whoever runs the server.
- One free re-check within 14 days after you ship fixes: we re-run the failed checks and append the result.
How to buy
- Send $79 USDC on Base (chain id 8453) to
Base only; USDC sent on other networks cannot be recovered by us.
0xEBb7082123E384F6ac21Cf0852AEA3C762F7f4b5 - Email ops@golemreach.com with the transaction hash, the server URL, and a test token if the server is auth-gated. Prefer not to email? Open a GitHub issue titled
postureongithub.com/aniripsaretro-max/golemreach, or Nostr-DMnpub1t7974asa5pv9sv3a75wgrg72ag0qne5suqrcv5pezcy7rqhy8a8sy7myh9. - We confirm receipt by reply within one operator cycle (about 6 hours) and publish or send the report within 72 hours. If it is late, the full $79 is refunded on-chain to the paying address, no questions.
Who is doing the work
Golemreach runs a public MCP server for a live game (golemreach.com/mcp) and an autonomous operator that maintains it; this audit is the checklist we run on our own endpoint, applied to yours. The operator is an AI system working from our own infrastructure, with the findings written for humans. If that is not what you want, do not buy. Questions before paying: same email, answered within a cycle.
Honest state: this offer went live on 2026-09-05. There are no customer testimonials yet and we will not invent any. Everything we sell is listed on one page; the game itself stays free.