{"product_id":"mcp-security-reviewer","title":"MCP Security Reviewer","description":"\u003cp\u003eMCP Security Reviewer checks an MCP server or client config before you connect it to Claude. Give it the server code, the tool definitions and your claude_desktop_config.json or connector settings, and it returns findings by severity with the file and line, the evidence, a short exploit scenario and the fixed code.\u003c\/p\u003e\u003cp\u003eBuilt for developers shipping MCP servers and teams deciding which third-party servers to allow. It looks for prompt injection through tool results and descriptions, tool poisoning and silent description changes, over-broad scopes, token passthrough, tokens in logs or URLs, missing audience checks, SSRF, command injection and path traversal, unauthenticated remote endpoints, local servers exposed on 0.0.0.0, secrets in config files and unpinned packages. It is a static review and never runs an untrusted server; it reviews security rather than designing tools.\u003c\/p\u003e\u003cp\u003e\u003cstrong\u003eFinds the holes an attacker would use\u003c\/strong\u003e before an MCP server gets access to your files, inbox or production API.\u003c\/p\u003e\u003cp\u003e\u003cstrong\u003eCompatible with:\u003c\/strong\u003e MCP TypeScript and Python servers, Cloudflare Workers remote MCP, Claude Desktop and Claude Code configs, Claude.ai connectors and other MCP clients.\u003c\/p\u003e\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eWhat is MCP tool poisoning?\u003c\/strong\u003e Hidden instructions in a tool description or result that steer the model; the reviewer flags them with the exact text.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDoes it check OAuth?\u003c\/strong\u003e Yes - token audience, scopes, passthrough, storage and redirect handling.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCan it review a server I did not write?\u003c\/strong\u003e Yes - paste the code or config; it never executes it.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eWhat do I get at the end?\u003c\/strong\u003e A findings table, a scope matrix per tool, a config review and a fix order.\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"KissMySkills","offers":[{"title":"Default Title","offer_id":58961478549768,"sku":null,"price":7.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1036\/1444\/7880\/files\/mcp-security-reviewer-1.png?v=1790983779","url":"https:\/\/kissmyskills.com\/es\/products\/mcp-security-reviewer","provider":"KissMySkills","version":"1.0","type":"link"}