Agent/MCP Audit Sprint

Focused review for tenant-scoped Remote MCP launch

Remote MCP Tenant Boundary Review

A USD $299 focused review for one Remote MCP server or external AI-client adapter where tools must stay tenant-scoped. The output is a launch boundary map, ranked failure modes, and release-gate tests for tenant context, tool catalogs, artifact indexes, audit events, redaction, approval gates, and prompt-injection handling.

FocusedUSD $299 Remote MCP Tenant Boundary Review
LaunchUSD $1,000 Remote MCP Launch Readiness Sprint
ScopeOne Remote MCP server or external adapter
Start RulePayment only after written scope acceptance

When to use it

Use this when MCP becomes an external tenant boundary

This is narrower than a full security audit and more specific than a generic auth review. It is for teams exposing selected internal capabilities to Claude, ChatGPT, Cursor, enterprise assistants, or other external AI clients through a Remote MCP surface.

Remote MCP server: HTTP, SSE, streamable HTTP, local connector, or hosted adapter exposing a controlled tool catalog.
Tenant-scoped data: case briefs, manifests, workspace records, evidence bundles, policy rules, tickets, docs, or customer-owned artifacts.
Internal harness boundary: MCP should adapt to internal tool contracts, permission gates, event logs, and policy decisions instead of becoming a second runtime.
Approval-gated tools: draft notes, evidence requests, write-like tools, and non-mutating draft flows that must return allowed, approval_required, or denied.
Launch decision: you need concrete tests before making the external tool catalog available to real users or tenants.

Release gates

What I check before the Remote MCP slice ships

The review follows one external call from client connection through auth resolution, index lookup, permission decision, tool execution, redaction, output schema validation, and audit recording.

Client input cannot be authoritative for tenant_id, raw artifact paths, raw database selectors, actor identity, or API-key identity.
Tenant and actor context is resolved before artifact lookup, permission checks, tool dispatch, cache reads, or audit event writes.
Unknown, stale, or cross-tenant case IDs return the same external denied/not-found shape while preserving precise reasons only in audit records.
Tool catalogs are derived from internal tool contracts and policy, not hard-coded as a parallel authorization model.
Read tools return structured, schema-valid, redacted outputs by default; raw PII and raw transcripts are intentionally unavailable.
Draft or write-class tools return approval_required or denied unless the permission gate explicitly allows a non-mutating draft.
Prompt-injection-shaped client or connector content is treated as data and produces a structured refusal or redacted output.
Audit events include bounded fields such as call id, tenant id, actor/key id, tool name, schema versions, input hash, case id, policy decision, redaction profile, outcome, and bounded error class.

USD $299 output

Focused review deliverables

The focused package covers one agreed Remote MCP server, connector, or adapter slice. It is designed for maintainers who already have an issue brief or implementation plan and need an outside no-execution launch pass.

Boundary map: client, auth resolver, tenant context, tool catalog, permission gate, artifact index, redaction layer, and audit sink.
Ranked launch risks: cross-tenant reads, tenant enumeration, stale manifests, bypassed permission gates, raw PII output, schema drift, and weak audit correlation.
Regression checklist: tenant A/B case tests, revoked key test, raw path rejection, prompt-injection fixture, draft approval gate, and schema-invalid fail-closed case.
Scope note: written decision on whether the first slice is ready, should stay read-only, or should upgrade to the USD $1,000 launch sprint.

Public checklist examples

Technical context before buying

These are public issue comments and not paid customer work. They show the kind of release-gate thinking this page turns into a scoped deliverable.

Payment packet

Copy after scope acceptance

Do not send secrets, API keys, private tenant data, raw transcripts, customer data, raw artifact paths, or production logs in public GitHub issues. Payment is requested only after the written scope is accepted.

Submit payment proof Review terms
Copyable packet I accept the Remote MCP Tenant Boundary Review package. Package: USD $299 Remote MCP Tenant Boundary Review Scope: [one Remote MCP server, hosted adapter, local connector, or external AI-client tool surface] Delivery: [public issue comment or private Markdown report] Payment timing: after written scope acceptance only. Ethereum address (ETH or ERC-20 USDC/USDT/DAI): 0xa7F2235a77FBc4eCcbF60923BCDF6Df74eC710FF Solana address (SOL or SPL USDC): 5CjUaMAsbXx2Hjczwoqi4MChTU1KjfUzbdiwPqZeceVM Payment proof form: https://github.com/jackjin1997/agent-audit-sprint/issues/new?template=payment-confirmation.yml