Kit A09 · MCP audits · 29 USD

Audit an MCP server the same way twice, and have something a client will pay for.

Any competent engineer can spot problems in an MCP server by reading the code. Very few can do it identically on the fifth server, write it up so a client acts on it, and charge for it. That gap is what this closes.

Price
29 USD
Human steps
4
Setup, once
20 min
Per week
15 min
Monthly cost
0 USD

MCP is how agents reach tools and data, which makes an MCP server a genuinely sensitive piece of infrastructure. The failure modes are documented and real: tool descriptions carrying prompt injection, over scoped tokens, confused deputy problems, tool shadowing.

Finding one of those once is a good afternoon. Turning it into a repeatable service is a different problem, and it is the one that stops people charging for this work. You need the same checks in the same order every time, a severity call you can defend, and a document the client can hand to an engineer. This kit is that layer, wrapped around mcp-doctor, the lab's open source, zero dependency CLI with 11 documented checks.

What is in the box

Skill 1

Run the audit

Drives the whole audit end to end, in a fixed order, so the fifth server gets the same treatment as the first. Gates explicitly on the protocol version caveat below rather than letting it silently skew a result.

Skill 2

Write the deliverable

Turns raw findings into something a client will act on: reproduction steps, severity triage, prioritised remediation, and a required limitations section.

Task

Weekly cadence

A scheduled task prompt that runs the offering on a weekly rhythm instead of whenever you remember to.

Install

Agentic installer

An installation protocol you hand to your own AI agent along with the unzipped kit. It reads the manifest, preflights your environment, installs the skills, registers the weekly task, and proves the install works before reporting done. Two of its checks exist to protect you: it watches the authorisation gate refuse a target with no permission record, and watches the cross check reject a report citing a finding the scan never produced.

Docs

Economics and kill criteria

The arithmetic, the break even, and the explicit conditions under which you should drop the offering rather than keep pushing it.

Docs

Risks and verification

VERIFY.md carries real command transcripts, not illustrative ones. RISKS.md covers the authorisation question properly.

What you have to do yourself

Four steps, about 20 minutes once and 15 minutes a week. Listed with timings in HUMAN_STEPS.md, each with the reason an agent cannot do it for you.

One of them does not bend: you need written authorisation before auditing a server you do not own. The kit refuses to help you skip that, and it is not squeamishness. Unauthorised probing of infrastructure you do not own is the kind of thing that ends a consulting reputation in one email.

Read this before buying, not after

There is a real protocol caveat. MCP spec revision 2026-07-28 removed the initialize handshake and the session id header. mcp-doctor 0.1.0 still sends the older protocol version, so a server that has fully migrated will fail its health check for protocol reasons rather than because anything is wrong with it. That is gated in the run skill, required as a limitations line in every report the kit produces, and it is kill criterion seven in ECONOMICS.md. Better you learn it here than in front of a client.

Founding buyers get the first audit run alongside them. Email the lab and your first audit is run with you: same fixed order, same severity calls, same report template every client gets, with a second pair of eyes on your target server in real time.

The CLI is free and open source. mcp-doctor costs nothing and you can read every line of it. What you are paying for is the layer that turns running it into a service you can sell: the fixed order, the report template, the severity calls, the cadence. If you would rather build that layer yourself, the CLI is right there, and that offer is meant.

The ladder this supports

The kit is the cheap end on purpose. It exists to make the paid work repeatable, and the paid work is 99 USD for a written security audit on one server. That figure lives on the engine page, which is the price authority for this site. Worth saying plainly: the lab's main business is now live quoting engines for home service contractors at ten thousand an install. The audit line stays open because the work is real, not because it is where the money is.

29 USDfounding price, one payment

No subscription and no running cost. One file, delivered by email as a download link.

Not for sale through a checkout on this site yet. We are opening the kits to the founding list first, on purpose. Leave an email below and the link comes to you directly, at this price.

No card details here and no checkout to load. One email, one download link, on the day it opens.

Get on the list

Leave your email and the download link arrives the day it opens, at the founding price, before it goes anywhere else.