Audit an MCP server the same way twice, and have something a client will pay for.
Any competent engineer can spot problems in an MCP server by reading the code. Very few can do it identically on the fifth server, write it up so a client acts on it, and charge for it. That gap is what this closes.
MCP is how agents reach tools and data, which makes an MCP server a genuinely sensitive piece of infrastructure. The failure modes are documented and real: tool descriptions carrying prompt injection, over scoped tokens, confused deputy problems, tool shadowing.
Finding one of those once is a good afternoon. Turning it into a repeatable service is a different problem, and it is the one that stops people charging for this work. You need the same checks in the same order every time, a severity call you can defend, and a document the client can hand to an engineer. This kit is that layer, wrapped around mcp-doctor, the lab's open source, zero dependency CLI with 11 documented checks.
What is in the box
Run the audit
Drives the whole audit end to end, in a fixed order, so the fifth server gets the same treatment as the first. Gates explicitly on the protocol version caveat below rather than letting it silently skew a result.
Write the deliverable
Turns raw findings into something a client will act on: reproduction steps, severity triage, prioritised remediation, and a required limitations section.
Weekly cadence
A scheduled task prompt that runs the offering on a weekly rhythm instead of whenever you remember to.
Agentic installer
An installation protocol you hand to your own AI agent along with the unzipped kit. It reads the manifest, preflights your environment, installs the skills, registers the weekly task, and proves the install works before reporting done. Two of its checks exist to protect you: it watches the authorisation gate refuse a target with no permission record, and watches the cross check reject a report citing a finding the scan never produced.
Economics and kill criteria
The arithmetic, the break even, and the explicit conditions under which you should drop the offering rather than keep pushing it.
Risks and verification
VERIFY.md carries real command transcripts, not illustrative ones. RISKS.md covers the authorisation question properly.
What you have to do yourself
Four steps, about 20 minutes once and 15 minutes a week. Listed with timings in HUMAN_STEPS.md, each with the reason an agent cannot do it for you.
One of them does not bend: you need written authorisation before auditing a server you do not own. The kit refuses to help you skip that, and it is not squeamishness. Unauthorised probing of infrastructure you do not own is the kind of thing that ends a consulting reputation in one email.
There is a real protocol caveat. MCP spec revision 2026-07-28 removed the initialize handshake and the session id header. mcp-doctor 0.1.0 still sends the older protocol version, so a server that has fully migrated will fail its health check for protocol reasons rather than because anything is wrong with it. That is gated in the run skill, required as a limitations line in every report the kit produces, and it is kill criterion seven in ECONOMICS.md. Better you learn it here than in front of a client.
Founding buyers get the first audit run alongside them. Email the lab and your first audit is run with you: same fixed order, same severity calls, same report template every client gets, with a second pair of eyes on your target server in real time.
The CLI is free and open source. mcp-doctor costs nothing and you can read every line of it. What you are paying for is the layer that turns running it into a service you can sell: the fixed order, the report template, the severity calls, the cadence. If you would rather build that layer yourself, the CLI is right there, and that offer is meant.
The ladder this supports
The kit is the cheap end on purpose. It exists to make the paid work repeatable, and the paid work is 99 USD for a written security audit on one server. That figure lives on the engine page, which is the price authority for this site. Worth saying plainly: the lab's main business is now live quoting engines for home service contractors at ten thousand an install. The audit line stays open because the work is real, not because it is where the money is.
No subscription and no running cost. One file, delivered by email as a download link.
Not for sale through a checkout on this site yet. We are opening the kits to the founding list first, on purpose. Leave an email below and the link comes to you directly, at this price.
No card details here and no checkout to load. One email, one download link, on the day it opens.
Get on the list
Leave your email and the download link arrives the day it opens, at the founding price, before it goes anywhere else.