Public checklist
23+ GitHub stars
The open MCP pentesting checklist buyers use to inspect tool safety, prompt injection, auth, and trust boundaries.
Type to search across all pages
Scoped, non-disruptive testing for AI-powered applications and Model Context Protocol implementations. We focus on tool boundaries, data access, and configuration so you can understand risk without operational surprises.
Authors of the MCP pentesting checklist.
Public checklist
The open MCP pentesting checklist buyers use to inspect tool safety, prompt injection, auth, and trust boundaries.
Training lab
An intentionally vulnerable lab that makes real MCP attack paths concrete before a client engagement starts.
Operating model
We confirm tools, data paths, connected systems, and exclusions in writing before anything starts.
Attackers move through MCP by chaining transport messages, tool calls, and returned data. We model those paths end-to-end so you can see where controls should live and how they can be bypassed.
A tool accepted unrestricted file paths over stdio, allowing the model to read configuration files outside the intended working directory.
Prompt injection shows up when attackers steer model behavior through untrusted content. We model those behaviors inside real MCP workflows so the testing reflects how tools, data, and instructions interact in production.
Untrusted tool output was reinserted into the system prompt, enabling extraction of internal runbook snippets.
Guardrails are only useful if they hold under adversarial input and real execution paths. We model how prompts, tool outputs, and external data hit those controls, then test the runtime paths where limits, allowlists, and policy checks should stop unsafe actions.
A safety policy existed in configuration but was not enforced in the runtime path used by background tool calls.
OAuth is the control plane for most AI vendors and MCP tools. Attackers look for over-scoped grants, long-lived refresh tokens, and cross-tenant consent paths they can reuse. We model those behaviors across real tool chains so the testing reflects how tokens actually move between services.
A vendor-issued refresh token remained valid after access was revoked, allowing continued data pulls from a connected workspace.
Attackers chain prompts, tools, and tokens rather than relying on a single weakness. We map those paths and test how controls behave in the exact workflows your teams run.
Transport validation, tool authorization, and data exposure paths across MCP.
Learn moreRAG data boundaries, embeddings pipelines, and API integration abuse paths.
Learn moreTool controls, memory boundaries, and privilege escalation paths in agents.
Learn moreWhy teams trust AI and MCP reviews here
Review the checklist, lab, tooling, and reporting model before you decide how to scope AI or MCP security work.
Practice lead
Founder & CEO
Akash leads Appsecco's product security testing practice and the public research behind its methods, labs, and reporting standards.
The public body of work matters for AI and MCP because you can verify whether the team has already mapped the protocol boundaries and abuse paths before engaging.
MCP pentesting checklist
23+ GitHub starsThe public checklist used by security teams to reason about tool safety, prompt injection, auth, and supply-chain trust in MCP systems.
Vulnerable MCP servers lab
157+ GitHub starsA training lab for making MCP attack paths concrete instead of theoretical.
MCP client and proxy
12+ GitHub starsInterception tooling for stdio-based MCP reviews and practical tool-path testing.
Use the flagship MCP page, report standard, and guide material to understand how AI and MCP scope is framed.
Standalone MCP service page
Flagship routeThe direct commercial overview of MCP methodology, pricing, deliverables, and protocol-specific testing depth.
Sample report
Evidence standardA public look at the report discipline that sits behind AI and MCP engagements.
AI red teaming guide
Scoping logicA guide that shows how Appsecco frames AI application testing, tool abuse, and workflow-level risk.
What clients say about AI security testing
We worked with Appsecco on a comprehensive security assessment of the AI capabilities we are building and releasing across our platform. The engagement was thorough and went well beyond a surface-level security review.
Harshit Agarwal
CEO & Co-Founder, Appknox
Attended the session on Demystifying MCP and AI Agent Security—really insightful! Learned practical techniques to identify vulnerabilities in AI agent implementations and gained a better understanding of balancing innovation with security. A productive and eye-opening Mastery Day.
Anonymous customer
Reference-ready next step
We can start from the checklist, lab, report example, or flagship MCP scope page that best matches the system you are reviewing.
Public protocol work matters here because AI and MCP risk depends on concrete tool, transport, auth, and data-flow behavior.
Request scoped reviewWe scope the actual AI workflows, connected tools, MCP servers, data sources, approval gates, and OAuth paths your product relies on. We test the real attack path from prompt to action, not just one isolated component.
We focus on your implementation: prompt construction, retrieval, tool use, MCP boundaries, token handling, and output controls. We also review how vendor-issued permissions and integrations are used in your stack.
Yes. Many teams need one assessment that covers AI application behavior together with MCP server exposure. We can scope both so the findings reflect the full production and runtime path.
Usually we need a staging environment, scoped credentials, architecture context, and enough access to exercise the in-scope flows. If production validation is required, we agree the exact limits and safe methods before testing begins.
You receive prioritized findings, attack-path narratives, tool or integration-specific evidence, practical remediation guidance, and retest support so engineering and security reviewers can validate fixes clearly.
Explore AI security testing
Move from AI security concepts into testing scope, agent risks, prompt injection, MCP exposure, and practical assessment paths.
How to evaluate MCP scope, public proof, connected-resource coverage, and reporting quality before launch.
A practical guide for separating workflow-level agent risk from MCP protocol and tool-path risk.
Security testing for LLM features, RAG workflows, prompt handling, tool calls, and connected data exposure.
Assessment of agent workflows, tool permissions, approval boundaries, memory handling, and autonomous actions.
Scoped testing for transport security, tool safety, prompt injection, OAuth hygiene, and access boundaries.
Adversarial testing for AI-enabled product behavior, tools, retrieval, agents, and workflows.
How to scope adversarial testing for LLM apps, RAG, agents, tools, MCP, and workflow actions.
How adversarial AI behavior testing fits with broader product and system security testing.
Risks and controls for LLM applications, RAG systems, embeddings, and model-connected workflows.
Share how your AI stack works. We will outline what we would test, what stays out of scope, and provide a fixed quote if that is useful.