One-time engagement
You wired up MCP. Do you know what it can do?
Most MCP setups grow one server at a time until nobody remembers what an agent can actually reach. The Token Audit is a one-time, outside look at your stack: what's exposed, what's ungoverned, and what to fix first.
Delivered within 5 business days of payment. Fixed scope, fixed price — no surprise invoice.
✗ github MCP server: write + delete scope, no approval gate ✗ stripe MCP server: live secret key readable by any agent process ! 3 servers with no audit log — actions untraceable after the fact Risk summary: 2 critical · 3 medium · 6 low Full report + fix plan delivered as a 1-page PDF
Three things every MCP stack gets wrong.
The audit isn't a generic checklist — it's a read of your actual config, your actual tools, and what an agent connected to them can actually do.
01
Tool-level exposure
Which of your MCP tools can read, write, or execute — and whether an agent can reach them without a human in the loop.
02
Auth & secret handling
API keys and tokens scoped correctly, or sitting in a config file an agent can read and leak.
03
Governance gaps
No audit trail, no approval gate, no policy layer — the three failure modes that turn a useful agent into a liability.
What's in the audit.
Fixed scope. You send me read access to your MCP configs (no write access needed, no code changes on your end), I read every server, and you get a report plus a call.
- Full read of every MCP server config in your stack
- Tool-by-tool risk classification (safe / needs a gate / remove)
- Secret and credential exposure check
- Prioritized hardening plan, ranked by risk vs. effort
- 1-page report you can hand to a compliance team
- 30-minute walkthrough call to go through findings
MCP Token Audit
$1,500
One-time, fixed price. Delivered as a report plus a 30-minute walkthrough. No retainer, no upsell required to get value.
Prefer to talk first? Book a free 15-min call or email jrm@fusional.dev.