Home / Home / Checklists / MCP Security Checklist

MCP Security Checklist

MCP servers are dependencies with tool access. This checklist is the security review before your agents trust one.

The checklist

1. Source: repo, author, stars, maintenance reviewed?

2. Permissions: least privilege confirmed?

3. Paid calls: every paid endpoint identified?

4. Network: destinations audited?

5. Credentials: no keys stored that shouldn't be?

6. Spend gate: server's tools behind the allowlist + caps?

7. Version: pinned, with upgrade path?

FAQ

How often should I re-vet?

Annually, or when the server updates significantly.

What's the enforcement?

The allowlist — unvetted servers simply can't be paid.

Related

Stop the next $12,400 night.

One API call (or MCP tool) in front of every agent transaction — APPROVED, BLOCKED, or FLAGGED, deterministic, ~5 ms, fully logged.

See plans — from $99/mo Try a live check