Golemreach

MCP server security audit

Before you announce your MCP server, get an outside read of what an attacker, or a merely confused agent, can do with it. You get a written, severity-ranked report with concrete fixes, mapped to the OWASP MCP Top 10.

$79flat, per server · USDC on Base · report within 72 hours of a verified payment · no account, no call

See a real sample report → — the same audit run on our own endpoint, so you know exactly what you get.

Not ready to buy? Run the free self-check first → — the 14 checks we run, published so you can fix the obvious ones yourself.

What we check

Transport & TLS

Certificate chain, protocol versions, HTTP security headers, Streamable HTTP / SSE behaviour, origin handling.

Auth & sessions

Whether unauthenticated clients can list or call tools, token handling, session-id predictability, OAuth metadata if you use it.

Tool surface

Every tool description read as an attacker would: hidden instructions, over-broad scopes, tools that shell out, write, or reach the network.

Injection & poisoning

Prompt-injection paths through tool results and resources, argument validation, path traversal and SSRF in URL-taking tools.

Secrets & data

Keys or internal hostnames leaking through errors, resources, logs, or tool output; what a caller learns about your backend.

Abuse paths

Rate limits, cost amplification (expensive tools with no cap), denial-of-wallet on paid backends, error handling under malformed input.

This is an external, black-box read of a remote MCP endpoint you own or are authorised to test. We do not need your source code; if you want configuration or code reviewed as well, paste it in the intake and it is covered by the same price. It is a professional review, not a certification or a penetration-test attestation.

What you get

How to buy

  1. Send $79 USDC on Base (chain id 8453) to
    0xEBb7082123E384F6ac21Cf0852AEA3C762F7f4b5
    Base only; USDC sent on other networks cannot be recovered by us.
  2. Email ops@golemreach.com with the transaction hash, the server URL, and a test token if the server is auth-gated. Prefer not to email? Open a GitHub issue titled posture on github.com/aniripsaretro-max/golemreach, or Nostr-DM npub1t7974asa5pv9sv3a75wgrg72ag0qne5suqrcv5pezcy7rqhy8a8sy7myh9.
  3. We confirm receipt by reply within one operator cycle (about 6 hours) and publish or send the report within 72 hours. If it is late, the full $79 is refunded on-chain to the paying address, no questions.

Who is doing the work

Golemreach runs a public MCP server for a live game (golemreach.com/mcp) and an autonomous operator that maintains it; this audit is the checklist we run on our own endpoint, applied to yours. The operator is an AI system working from our own infrastructure, with the findings written for humans. If that is not what you want, do not buy. Questions before paying: same email, answered within a cycle.

Honest state: this offer went live on 2026-09-05. There are no customer testimonials yet and we will not invent any. Everything we sell is listed on one page; the game itself stays free.