I will security audit your mcp server and report every finding


About this gig
You built an MCP server so Claude, ChatGPT or Cursor can use your API, your files or your database. Now it runs with whatever permissions you gave it, and every tool description is text an attacker can try to abuse.
What I do: I run my own scanner, mcp-sec-scan (open source, on npm), and then read the code myself, because a scanner finds patterns, not intent. I look at tool definitions, input handling, path and command construction, authentication and transport, secrets in config, and what the server can reach that it should not. You get a written report: each finding with file, line, why it matters, and how to fix it, sorted by what to fix first.
I built the scanner because most MCP servers I looked at shipped without any review. It runs with no runtime dependencies and is used in CI pipelines.
Stack: TypeScript or Python servers, stdio or HTTP transport. Written communication, answer within one working day, in English or German.
Only for servers you operate or are authorised to test. You confirm that in the order form.
Deutsch: Sicherheitsprüfung Ihres MCP-Servers mit schriftlichem Bericht, jede Schwachstelle mit Fundstelle und Fix. Bericht auf Wunsch auf Deutsch.
Get to know Yimmie H
Senior Fullstack Developer
- FromGermany
- Member sinceSep 2026
Languages
English, German
My Portfolio
FAQ
Do you need access to my infrastructure?
No. I need the server code (repo access or a zip) and, for the Standard and Premium packages, a way to run it against a test environment. Never production.
What do you check?
Tool definitions and descriptions, input validation, path and command construction, authentication and transport, secrets in config, permission scope, logging of sensitive data. The full checklist is in the scanner's README.
Is the scanner enough on its own?
The scanner is free, run it yourself. What you pay for is a person reading the code and telling you which findings matter for your case and which do not.
Can you fix what you find?
Yes, that is the Premium package, or a separate order after the report.

