Sample evidence
Agent/MCP Audit Sample Reports
Three public-code samples show the paid sprint format: scoped evidence, boundary map, ranked findings, fix plan, and launch notes. They are independent samples, not private vulnerability disclosures.
Samples3 real public repos
OutputBoundary map + ranked findings
AutomationNo-execution intake triage
Paid SprintUSD $1,000 fixed
Sample 01
douban-mcp
Public MCP server and CLI with auth, cookie handling, external scraping, write-capable tools, and agent-facing output.
High: Remote SSE should document binding and exposure policy.
Medium: Write tools rely on env opt-in but need operator confirmation notes.
Low: Cookie validation can distinguish login from write readiness.
Pass: Cookie redaction paths cover common axios/pino shapes.
Sample 02
firecrawl-mcp-server
Public MCP server with hosted and local transports, OAuth/API-key auth, monitor tools, open-web actions, and local file parsing.
Medium: Remote transport exposure policy is scattered across code and docs.
Medium: Local file parse needs an explicit trust boundary.
Medium: CI builds, but does not prove auth/tool regressions stay fixed.
Low: Feedback write surfaces deserve retry/error regression tests.
Sample 03
browserbase/mcp-server-browserbase
Public browser automation MCP server with stdio and Streamable HTTP transports, Browserbase sessions, page actions, observation, and extraction tools.
Medium: HTTP transport needs an operator-facing exposure matrix.
Medium: Browser action tools need explicit launch-mode policy.
Low: Operational logs should be treated as sensitive artifacts.
Pass: Local install, build, and tests passed in the sample review.
Start path
Turn a public repo into a scoped paid sprint
- Open the audit intake issue with the public repo URL and highest concern.
- The automated triage clones the public repo, reads files, and posts scanner findings without executing target code.
- Scope is accepted for one repo or product slice.
- Payment is confirmed via ETH, SOL, or an agreed invoice-first path before work starts.