MCP Security Checklist
MCP servers are dependencies with tool access. This checklist is the security review before your agents trust one.
The checklist
1. Source: repo, author, stars, maintenance reviewed?
2. Permissions: least privilege confirmed?
3. Paid calls: every paid endpoint identified?
4. Network: destinations audited?
5. Credentials: no keys stored that shouldn't be?
6. Spend gate: server's tools behind the allowlist + caps?
7. Version: pinned, with upgrade path?
FAQ
How often should I re-vet?
Annually, or when the server updates significantly.
What's the enforcement?
The allowlist — unvetted servers simply can't be paid.
Related
Stop the next $12,400 night.
One API call (or MCP tool) in front of every agent transaction — APPROVED, BLOCKED, or FLAGGED, deterministic, ~5 ms, fully logged.
See plans — from $99/mo Try a live check