I will security audit your mcp server and report every finding

Y
yimmie_h
Y
yimmie_h
Yimmie H

About this gig

You built an MCP server so Claude, ChatGPT or Cursor can use your API, your files or your database. Now it runs with whatever permissions you gave it, and every tool description is text an attacker can try to abuse.


What I do: I run my own scanner, mcp-sec-scan (open source, on npm), and then read the code myself, because a scanner finds patterns, not intent. I look at tool definitions, input handling, path and command construction, authentication and transport, secrets in config, and what the server can reach that it should not. You get a written report: each finding with file, line, why it matters, and how to fix it, sorted by what to fix first.


I built the scanner because most MCP servers I looked at shipped without any review. It runs with no runtime dependencies and is used in CI pipelines.


Stack: TypeScript or Python servers, stdio or HTTP transport. Written communication, answer within one working day, in English or German.


Only for servers you operate or are authorised to test. You confirm that in the order form.


Deutsch: Sicherheitsprüfung Ihres MCP-Servers mit schriftlichem Bericht, jede Schwachstelle mit Fundstelle und Fix. Bericht auf Wunsch auf Deutsch.

Get to know Yimmie H

Yimmie H

Senior Fullstack Developer

  • FromGermany
  • Member sinceSep 2026
  • Languages

    English, German
I am a Fullstack Developer specializing in PHP/Symfony/Laravel and React/Next.js/TypeScript. I have extensive experience migrating legacy codebases to modern frameworks and maintaining production e-commerce systems. My expertise includes Wordpress, WooCommerce, CI/CD automation, REST API design, and MCP server security.

My Portfolio