Agent/MCP Audit Sprint

48-hour async review for teams shipping agent tools

Agent/MCP Security Review Packages

Start with a $99 quick scan, a $299 focused review, or the $1,000 full audit sprint. I review agent and MCP products for the practical failure modes that break launches: tool boundaries, secrets, auth, prompt/tool injection, test gaps, and deployment assumptions.

Entry
$99 quick scan
Focused
$299 same-day review
Emergency
$1,000 cost spike sprint
Scope
1 repo or product slice

New direct $1,000 path

AI Cost Spike Emergency Sprint for runaway LLM bills

When a live agent, RAG workflow, support bot, coding-agent loop, or model API bill is already spiking, the useful offer is not another generic audit. This package produces a 24h containment plan: spend-driver map, loop caps, retry budgets, retrieval limits, model-routing changes, cache candidates, and instrumentation guardrails.

Open the AI Cost Spike Emergency Sprint page Estimate OpenRouter spend before choosing a package Reconcile OpenRouter actual cost against product display Open the emergency intake Use TokenMeter before the scope note
$1,000AI Cost Spike Emergency Sprint after written scope acceptance
Target24h containment plan for one runaway AI workflow or model bill spike
EvidenceSanitized usage totals, model mix, retry counts, TokenMeter snapshot, or redacted trace summary
GuardrailNo private prompts, secrets, customer data, or raw production traces in public issues

Free LLM cost estimator

OpenRouter Cost Calculator for model spend triage

For teams comparing model routes or seeing unexpected OpenRouter spend, the calculator turns monthly requests, token volume, cache-read share, retry overhead, and tool-call fanout into a sanitized intake packet. The actual-cost reconciliation page compares product display against usage.cost or generation total_cost when provider billing disagrees. The 402 brownout runbook handles insufficient credits, stale balance states, max_tokens caps, and retry containment. These route small checks to the USD $99 quick audit, recurring leaks to the USD $299 cost review, and urgent burn-rate problems to the USD $1,000 emergency sprint.

Open the OpenRouter Cost Calculator Open the OpenRouter Actual Cost Reconciliation Open the OpenRouter Balance Guardrail Open the OpenRouter 402 Brownout Runbook Open the LiteLLM Budget Guardrail Open TokenMeter quick audit path Open TokenMeter emergency path
$99Quick AI API Cost Audit for a small model-mix or launch-pricing sanity check
$299AI Agent Cost Leak Review for cache misses, retry loops, RAG bloat, or model-routing drift
$1,000AI Cost Spike Emergency Sprint when daily burn already needs containment
ActualProvider actual cost, generation id, cache-read tokens, and retry dedupe need one source of truth
GateBalance display, key limit, stale snapshot, and reservation checks before dispatch
402Insufficient credits, waiting-credit states, max_tokens caps, and retry storms need a stop rule
LiteLLMPer-user, per-agent, and per-team quota gates need policy snapshots and reconciliation
SafeCopy sanitized counts only; no private prompts, keys, customer data, or raw traces in public issues

Fast paid music test

AI Music Generator storefront for a $29 first order

Not every visitor is ready to buy a security audit. The AI music storefront routes SaaS/Product Hunt launch videos, ecommerce product videos, boosted Reels that need custom ad-safe music, YouTube videos with claimed or risky music sections, local ads, UGC agency client approval hooks, real estate listing videos, wedding highlights, podcast intros, sponsor segments, and creator intros into one brief-first paid path. Payment is still requested only after the written music brief and package are accepted.

Open the AI Music Generator storefront Calculate the right AI music package Generate the AI music order packet Open the same-day $49 AI music rush packet Copy the AI music commercial-use packet Replace music for a boosted Reel or paid social ad Replace music for a YouTube copyright claim Open SaaS $29 prefilled order desk Open product $29 prefilled order desk Open rush $49 prefilled order desk Open YouTube claim $49 prefilled order desk Open UGC $149 prefilled order desk Open podcast $149 prefilled order desk Hear sample-to-order packets Copy the $29 AI music brief Open SaaS launch video music page Open product video music page Open short-form ad music page Open boosted Reel ad music page Open YouTube claim music page Open UGC agency music hook page Open AI music order form
$29USD $29 Founding Hook Sketch for one short approved direction
$49Same-Day Hook Sketch for a narrow 8-15 second rush brief after availability is confirmed
CalcPricing calculator routes simple hooks, two-direction checks, campaign packs, and launch kits before payment
$149Ad Music Pack with selected variants, cut plan, one revision pass, and usage notes
UseSaaS/Product Hunt launch videos, product videos, ads, Reels, Shorts, UGC videos, listing videos, wedding highlights, podcast intros, sponsor cues, and creator intros
GuardrailPayment after written brief acceptance only; no known-artist soundalikes or third-party lyrics without rights

What ships

A review a maintainer can act on immediately

01

Boundary Map

Every tool, transport, credential, external API, and write action mapped into read-only, write, destructive, and privileged paths.

02

Risk Findings

Ranked issues with reproduction steps, evidence, affected files, severity, impact, and the lowest-risk fix path.

03

Test Plan

Concrete tests for tool contracts, auth gates, secret redaction, retry behavior, and failure states that agents commonly trigger.

04

Launch Notes

Short handoff covering what to fix now, what to monitor, and what to defer without increasing customer-facing risk.

Sample evidence

Based on real public repos, not a synthetic demo

The sample audits cover five public-code targets: douban-mcp, a public MCP server + CLI with auth, write tools, and external scraping; firecrawl-mcp-server, a production MCP server with hosted/local transports, OAuth, monitor tools, and local parsing; browserbase/mcp-server-browserbase, a browser automation MCP server with stdio and HTTP transports, sessions, page actions, observation, and extraction tools; jackjin1997/sentinel, a self-owned autonomous incident-response agent; and jackjin1997/agentgap, a self-owned agent config and MCP bridge.

Open the douban-mcp sample report Open the Firecrawl MCP sample report Open the Browserbase MCP sample report Open the Sentinel dogfood report Open the AgentGap dogfood report Compare all five sample reports
HighRemote SSE should document binding and exposure policy
MedBrowserbase HTTP transport needs an explicit exposure matrix
LowOperational logs should treat URLs, sessions, and downloads as sensitive artifacts
PassBrowserbase sample passed pnpm install, build, and tests

Best fit

For founders and maintainers who already have something running

MCP servers with local or remote transports
Agent tools that touch user accounts or external APIs
AI cost spike emergency sprints for runaway LLM bills, agent loops, retry storms, and launch-pricing risk
OpenRouter model spend estimates for cache-read assumptions, retry overhead, tool-call fanout, and package routing
OpenRouter actual-cost reconciliation for product-display mismatch, provider usage.cost, generation id dedupe, and audit trail fixes
OpenRouter balance guardrails for credits, key limits, stale states, and pre-dispatch reservations
OpenRouter 402 brownout reviews for insufficient credits, waiting-credit states, max_tokens caps, streaming fallback, and retry containment
LiteLLM budget guardrails for per-user, per-agent, and per-team quota enforcement
AI agent cost leak reviews for token spend, RAG bloat, model-routing drift, retry loops, cache misses, and coding-agent tool-call loops
Agent auth and cookie vault reviews for token brokers, site_login flows, OAuth/HITL consent, and authenticated scraping
Remote MCP tenant boundary reviews for tenant-scoped tool catalogs, artifact indexes, audit events, redaction defaults, and approval-required draft tools
MCP SSRF focused reviews for pagination URLs, callbacks, redirects, webhooks, proxy fetches, and credential-bearing dynamic URL fetches
CLI-to-agent bridges before a public launch
LLM workflows with write actions, publishing, or secrets
Small teams that need a senior outside review without a long consulting process
Open-source maintainers preparing a paid cloud or hosted version

Free triage tool

Run the same first-pass scanner before booking

The repo includes a browser scanner for public GitHub URLs, a private local-file scanner, a Node script, and a reusable GitHub Action that scan an agent or MCP codebase for review signals: transports, write actions, credential paths, auth gates, redaction, tests, and CI.

Open the MCP server security scan page Open the MCP SSRF focused review page Open the AI cost spike emergency page Open the OpenRouter cost calculator Open the OpenRouter actual cost reconciliation page Open the OpenRouter 402 brownout page Open the LiteLLM budget guardrail Open the AI agent cost leak review page Open the AI agent security audit page Open the AI Agent Security Radar Open the MCP Security Radar Use the GitHub Code Scanning workflow Paste a public GitHub URL Use the scanner Open the MCP security checklist
Runnpm exec --yes github:jackjin1997/agent-audit-sprint -- /path/to/repo
JSONnpm --silent run audit:repo -- /path/to/repo --json
SARIFuses: jackjin1997/agent-mcp-code-scan-action@v1 with sarif: "true"
ThenBook the paid sprint for human review and fix planning

Ready to start

Generate a clean audit request brief

Use this local-only builder to prepare the exact scope, delivery preference, and payment network before opening a GitHub request. Public GitHub repo requests get an automated no-execution scanner triage comment before paid scope acceptance.

Open request

Payment

Fixed price, crypto-ready, invoice-first friendly

Open an audit request, include the repo/product slice, and pay after scope is accepted. ETH, ERC-20 USDC/USDT/DAI, SOL, and SPL USDC are ready now; if you need an invoice-first discussion, choose that option in the intake form.

Review the Statement of Work before payment Open the fixed $1,000 quote
  1. Open an intake issue with the repo, scope, preferred network, and asset.
  2. Pay $1,000 after scope is accepted, or request invoice discussion first.
  3. Reply with the transaction hash; the audit starts after confirmation.
Ethereum
Ethereum payment address QR code 0xa7F2235a77FBc4eCcbF60923BCDF6Df74eC710FF

Accepted assets after scope acceptance: ETH or ERC-20 USDC/USDT/DAI.

Solana
Solana payment address QR code 5CjUaMAsbXx2Hjczwoqi4MChTU1KjfUzbdiwPqZeceVM

Accepted assets after scope acceptance: SOL or SPL USDC.

Operator

Zexu Jin

Backend engineer focused on Agent Harness, Tool Use, MCP, Evals, and AI infrastructure.