Agent/MCP Audit Sprint

Focused review for tool-callable URL fetches

MCP SSRF and Dynamic URL Fetch Review

A USD $299 focused security review for one MCP or agent URL-fetch boundary: fetch_pagination_url, callback URL, redirect URL, webhook URL, proxy URL, download URL, or any tool path where an attacker-controlled URL can be fetched with nearby cookies, bearer tokens, API keys, or internal network reach.

EntryUSD $99 Quick Scan
FocusedUSD $299 MCP SSRF Focused Review
FullUSD $1,000 Full Audit Sprint
Start RulePayment only after written scope acceptance

When to use it

Use this when URLs become agent inputs

This package is for teams that already know the risky seam: a tool accepts a URL, follows a URL from a provider response, proxies a URL for the user, or mixes dynamic fetch behavior with logged-in browser state.

Pagination: next_url, pagination_url, or fetch_pagination_url returned by an API or page.
Callback/redirect: OAuth, webhooks, redirect handlers, or user-provided callback URLs that trigger server-side fetches.
Proxy/download: fetch tools that retrieve arbitrary URLs, files, screenshots, documents, or remote page content.
Credentials nearby: bearer tokens, cookies, API keys, auth sessions, browser profiles, or workspace connectors near the fetch path.
Hosted MCP: remote transports where an external client can influence the URL target.

Review checklist

What I check in the fetch boundary

The review follows a dynamic URL from tool input or provider response to DNS, redirects, credential attachment, logs, cache writes, and error output.

Scheme, host, port, eTLD+1, redirect, and final-target validation before any credential-bearing request.
Blocks for localhost, link-local, RFC1918 ranges, metadata IPs, non-HTTP schemes, IPv6 edge cases, and DNS rebinding assumptions.
Credential stripping for attacker-influenced URLs and separation between user-authenticated fetches and public fetch tools.
Tests for unsafe redirects, sibling domains, mixed-case schemes, encoded hosts, metadata endpoints, and private network targets.
Redaction for URLs, Authorization headers, cookies, request configs, response configs, traces, screenshots, and tool output.
Operator-facing launch gates for hosted MCP transports, proxy modes, and user-provided URL features.

USD $299 output

Focused review deliverables

This is narrower than a full audit: one dynamic URL fetch boundary, one evidence path, and a concrete test checklist that a maintainer can add before shipping.

Boundary map: URL source, validation point, redirect policy, credential source, network reach, cache/log sinks, and tool output.
Ranked risks: concise findings with evidence, impact, and lowest-risk fix path.
Regression checklist: SSRF cases for metadata IPs, local/private ranges, unsafe redirects, non-HTTP schemes, sibling domains, and credential forwarding.
Launch guardrails: allowlist policy, no-credential fetch mode, redaction expectations, and hosted transport acceptance criteria.
Upgrade path: if the boundary expands into broader auth, browser, or write-tool risk, the full USD $1,000 sprint can be scoped separately.

Scanner evidence

Start from a free scan or SARIF alert

The browser scanner and CLI scanner both flag dynamic URL fetch and SSRF-with-credentials evidence. Attach that output to the focused review so the paid scope starts with a concrete path.

Payment packet

Copy after scope acceptance

Do not send private tokens, cookies, production URLs with secrets, or customer data in public GitHub issues. Payment is requested only after the written scope is accepted.

Submit payment proof Review terms
Copyable packet I accept the MCP SSRF and Dynamic URL Fetch Review package. Package: USD $299 MCP SSRF Focused Review Scope: [one pagination, callback, redirect, webhook, proxy, or dynamic URL fetch boundary] Delivery: [public issue comment or private Markdown report] Payment timing: after written scope acceptance only. Ethereum address (ETH or ERC-20 USDC/USDT/DAI): 0xa7F2235a77FBc4eCcbF60923BCDF6Df74eC710FF Solana address (SOL or SPL USDC): 5CjUaMAsbXx2Hjczwoqi4MChTU1KjfUzbdiwPqZeceVM Payment proof form: https://github.com/jackjin1997/agent-audit-sprint/issues/new?template=payment-confirmation.yml