The MCP Audit Checklist

10 checks before you trust any MCP server.

The Model Context Protocol gives AI agents direct access to your tools and data. Run these ten checks against every MCP server in your stack — before an agent does something you cannot undo.

Server Identity & Provenance
01
Verify the server’s source and maintainer.

Confirm the repository, publisher, and release signature. Unofficial mirrors and typosquatted packages are the #1 MCP supply-chain vector.

02
Pin the exact version you audited.

A server that auto-updates is a server you have not audited. Pin versions and re-audit on every bump.

03
Inventory every tool the server exposes.

List each tool function, its parameters, and what systems it can reach. If you cannot enumerate it, you cannot govern it.

Permissions & Boundaries
01
Scope credentials to least privilege.

The server should hold tokens scoped to exactly the resources its tools need — never a personal access token or admin key.

02
Separate read paths from write paths.

Tools that mutate state (write, delete, deploy, send) deserve separate approval thresholds from read-only tools.

03
Confirm no tool can escalate its own scope.

Check for tools that can create credentials, modify permissions, or install other tools. These are escalation primitives.

04
Test prompt-injection resistance on tool outputs.

Any tool returning external content (web pages, tickets, emails) can carry instructions back to the agent. Sanitize or wrap untrusted output.

Runtime & Audit
01
Log every tool call with arguments and results.

An immutable record of what was called, by which session, with what parameters — or you cannot reconstruct an incident.

02
Define a kill-switch before you need it.

Know exactly how to revoke the server’s credentials and halt in-flight sessions, and test that path.

03
Re-run this checklist quarterly.

Servers add tools between versions. A passing audit six months ago says nothing about the tools added since.

© 2026 Cyber Strategy Institute · Engineered Certainty Protocol cyberstrategyinstitute.com

Stop Threats Before They Execute

Your free Kernel-Level Defense Buyer’s Guide is ready to download.

By providing my email address, I consent to receive emails and text messages—including newsletters and marketing communications—from creators of Warden Secure, Cyber Strategy Institute, our flagship zero-trust platform for ransomware prevention, and agree to the Terms and Privacy Policy. You may unsubscribe at any time.