Resources · MCP

Score MCP and tool-server exposure without opening the cluster.

Identity, least privilege, audit trails, data classes, and shadow AI. Export a one-pager. Client systems stay in your environment.

A demo MCP server is not a security review

Off-the-shelf Model Context Protocol servers get a demo working. They do not answer who the agent is, which fields it can read, or where every tool call is logged. Teams then paste CRM notes into ChatGPT because the approved path cannot see internal systems. This checklist is the self-serve version of that gap: the same control conversation as MCP development, without asking you to paste a config.

Who this is for

  • Engineering and platform leads rolling out Claude, Cursor, or a custom agent onto CRM, EHR, ERP, or internal APIs.
  • InfoSec partners who will not sign unbounded tool access and want a shared list before the next review.
  • Teams that already know a filesystem MCP server on production is a joke, and need language for the rest of the org.

What you get

  • A scored snapshot across identity, tool design, audit, data classes, and install/shadow-AI controls.
  • A printable one-pager with banded results, not a vanity percentage.
  • A clear next step: tighten internally, or scope governed MCP with a named engineer.

Frequently asked questions

What is the MCP exposure checklist?

A scored questionnaire for engineering buyers assessing Model Context Protocol / tool-server exposure. You mark identity, least privilege, audit, data classes, and shadow-AI controls as in place, partial, or missing. You get a banded snapshot you can print. It is not a scan of your servers.

Do I need to upload an MCP config or a repo?

No. Client systems stay in your environment. The checklist never asks for a repository, a paste of production source, or server configs. If you need a named engineer to design the context layer, that is MCP development.

How is this different from the AI Code Risk Scorecard?

The scorecard is about Copilot, Cursor, and Claude Code in the repo. This checklist is about agents at runtime: which tools they can invoke, which data they can read, and whether every call is authenticated and logged. Different questionnaire. Different paid path.

Who should fill this out?

Staff/principal engineers, platform owners, and InfoSec partners who can answer how Claude, Cursor, or a custom agent actually reaches CRM, EHR, ERP, or internal APIs. Not a marketing pass.

Is a high score permission to roll out agents?

No. A stronger band means more of the expected controls exist. It is not a pentest, not an ATO, and not evidence a serious buyer will accept on its own. Questionnaires still want a threat model and an audit trail in code.

Why a work email?

Same gate as the other Resources tools. Unlock once per browser session, then score and export. We do not use it to upload your servers. There is nothing to upload.

Can I export the result?

Yes. After signup you can print or save a one-pager (your browser’s print-to-PDF) and copy Markdown. Copy is local to the browser.

What if we only use an official GitHub or Slack MCP server?

Say so honestly in the off-the-shelf row. Official servers are fine when the system and data sensitivity match. They are the wrong answer for proprietary APIs, PHI, or undocumented legacy. The enterprise MCP guide is the editorial version of that split.

How does this relate to HIPAA?

If PHI is in the tool path, treat MCP as a disclosure surface unless a BAA and minimum-necessary design say otherwise. Pair with the BAA / vendor access decision tree and Maxiom Labs for clinical systems.

Launch

Launch the checklist

Sign in with a work email, then run the tool in this page. Client code stays in your environment.

Work email to continue

Unlock MCP exposure checklist

Same gate as the AI Code Risk Checklist. Unlock once per browser session to use or export. Client code stays in your environment: this tool never asks for a repository.

  • Questionnaire only: no source upload
  • Print or save a one-pager from the browser
  • Unlocks the other Resources tools in this session

Work email unlocks the tool for this browser session. No repo upload.

Need a named engineer, not a worksheet?

A 30-minute scoping call is the usual next step when the snapshot is not enough.

  • NDA signed before access
  • Read-only repository only
  • Senior engineers every time
  • Report in 10 business days