All workflows

MCP Tool Surface Audit — Agent Tool Permission Risk

Inspect up to 100 caller-supplied MCP tool declarations for duplicate names, side-effect capabilities, missing schemas, read-only contradictions and least-privilege allowlist violations. Returns actionable indexed findings and SHA-256 inventory evidence. No network probing, malware scanning or external signature proof.

4 credits per call · $0.04 USDC with x402

Sample input

{
  "tools": [
    {
      "name": "search_docs",
      "description": "Retrieve documentation",
      "inputSchema": {
        "type": "object",
        "properties": {
          "q": {
            "type": "string"
          }
        }
      },
      "annotations": {
        "readOnlyHint": true
      }
    },
    {
      "name": "execute_shell",
      "description": "Run shell command on the agent host",
      "inputSchema": {
        "type": "object"
      },
      "annotations": {
        "readOnlyHint": true
      }
    }
  ],
  "policy": {
    "allow_tools": [
      "search_docs"
    ]
  }
}

Worked sample output

{
  "ok": true,
  "mode": "mcp-tool-surface-audit",
  "evaluated_tools": 2,
  "outcome": "manual_review",
  "metadata_risk_score": 62,
  "findings": [
    {
      "tool": "execute_shell",
      "severity": "high",
      "reason": "potential_side_effect",
      "categories": [
        "exec"
      ],
      "index": 1
    },
    {
      "tool": "execute_shell",
      "severity": "critical",
      "reason": "conflicting_read_only_annotation",
      "index": 1
    },
    {
      "tool": "execute_shell",
      "severity": "medium",
      "reason": "tool_not_in_caller_allowlist",
      "index": 1
    }
  ],
  "counts": {
    "critical": 1,
    "high": 1,
    "medium": 1
  },
  "inventory_sha256": "267d493d115327ef684f5515ca6c3e6a6bdd85c6cc28c00f0d0e44592c04a216",
  "assumptions": [
    "Only caller-provided tool declarations were inspected; no MCP server was contacted.",
    "Keyword signals are static heuristics, not a vulnerability scan or a tool-behavior guarantee.",
    "Tool descriptions and readOnly annotations may be inaccurate; enforce authorization outside this report."
  ],
  "charged_downstream": false,
  "server_called": false
}

Worked example using published sample data only. Own-data execution is paid.

Connect in curl

Set BOUNTY_API_KEY privately after your payment is verified. Change the retry key for each new logical request.

curl 'https://bounty-engineer-x402-prod.onrender.com/v1/prepaid/mcp-tool-surface-audit' \
  -H "Authorization: Bearer $BOUNTY_API_KEY" \
  -H 'Content-Type: application/json' \
  -H 'Idempotency-Key: workflow-request-001' \
  -H 'X-Max-Credits: 4' \
  --data '{"tools":[{"name":"search_docs","description":"Retrieve documentation","inputSchema":{"type":"object","properties":{"q":{"type":"string"}}},"annotations":{"readOnlyHint":true}},{"name":"execute_shell","description":"Run shell command on the agent host","inputSchema":{"type":"object"},"annotations":{"readOnlyHint":true}}],"policy":{"allow_tools":["search_docs"]}}'

Connect in n8n

Download the inactive n8n template. Import it, configure the private Header Auth credential, inspect the sample and run it manually. A new execution creates a new billable request; there is no automatic schedule.

Use an HTTP POST to https://bounty-engineer-x402-prod.onrender.com/v1/prepaid/mcp-tool-surface-audit. Send JSON and these headers; store the Bearer token as a private credential.

{
  "method": "POST",
  "headers": {
    "Authorization": "Bearer YOUR_PRIVATE_API_KEY",
    "Content-Type": "application/json",
    "Idempotency-Key": "UNIQUE_PER_LOGICAL_REQUEST",
    "X-Max-Credits": "4"
  },
  "body": {
    "tools": [
      {
        "name": "search_docs",
        "description": "Retrieve documentation",
        "inputSchema": {
          "type": "object",
          "properties": {
            "q": {
              "type": "string"
            }
          }
        },
        "annotations": {
          "readOnlyHint": true
        }
      },
      {
        "name": "execute_shell",
        "description": "Run shell command on the agent host",
        "inputSchema": {
          "type": "object"
        },
        "annotations": {
          "readOnlyHint": true
        }
      }
    ],
    "policy": {
      "allow_tools": [
        "search_docs"
      ]
    }
  }
}

Reuse a retry key only for the same input. Failed execution returns reserved credits. Full integration and recovery guide · Machine-readable recipe