Agent/MCP Audit Sprint

Statement of Work

$1,000 Agent/MCP Audit Sprint Terms

These terms are designed for a compact async engineering review. They set clear scope, payment, delivery, and data-handling expectations before private work begins.

PriceUSD $1,000 fixed
Turnaround48 hours after payment confirmation
ScopeOne repo or product slice

Included

Boundary mapTools, transports, credentials, external APIs, write actions, destructive paths, and privileged operations.
Risk findingsRanked issues with evidence, affected files, impact, and practical remediation path.
Test planFocused tests for schema parsing, auth gates, secret redaction, write-mode defaults, and transport assumptions.
Launch notesWhat to fix now, what to monitor, and what can safely wait.

Not Included

Payment And Start

Open the intake issue first. After scope is accepted, pay USD $1,000 equivalent via the selected network and asset, then submit the transaction hash through the payment proof form. Accepted crypto paths are ETH or ERC-20 USDC/USDT/DAI on Ethereum, and SOL or SPL USDC on Solana. If an invoice-first flow is needed, raise that before payment so the exact payment method and billing details are agreed before work starts. The 48-hour target starts after payment confirmation and scope acceptance.

Ethereum ETH or ERC-20 USDC/USDT/DAI 0xa7F2235a77FBc4eCcbF60923BCDF6Df74eC710FF
Solana SOL or SPL USDC 5CjUaMAsbXx2Hjczwoqi4MChTU1KjfUzbdiwPqZeceVM

Confidentiality And Data Handling

Do not paste secrets, private keys, cookies, customer data, production logs with sensitive values, or live credentials into GitHub issues. For private code or private docs, share only the minimum access needed and remove access after delivery.

Delivery

Delivery is a Markdown report unless otherwise agreed in the intake issue. The report can be public or private depending on the buyer's preference and repository sensitivity.