I will assess the security of your mcp server or ai tool integration
Senior Application Security Engineer
Informazioni su questo servizio
MCP (Model Context Protocol) servers are the newest, least-audited attack surface in AI right now. Most security tooling for it is still automated-scan-only; it tells you something's exposed but not whether it's actually exploitable.
I do both: discovery scanning to map your attack surface, plus manual exploit validation to prove real impact, not theoretical risk. You get evidenced findings (request/response proof, CWE classification, severity) and concrete remediation steps, not just a list of warnings.
Background: I built and published an open-source MCP security lab demonstrating a full discovery-to-exploit workflow against a real misconfiguration (CWE-22, path traversal), along with code and a write-up, publicly on GitHub, linked in my portfolio.
Note: I test servers/configs you own or have explicit authorization to test. I cannot test third-party or production systems without your confirmation of authorization.
Il mio portfolio
FAQ
Can you perform the test if I am not an owner of the system / there is no written authorization to test it?
No, in this case, the order cannot proceed

