MCP Tool Surface Audit — Agent Tool Permission Risk
Inspect up to 100 caller-supplied MCP tool declarations for duplicate names, side-effect capabilities, missing schemas, read-only contradictions and least-privilege allowlist violations. Returns actionable indexed findings and SHA-256 inventory evidence. No network probing, malware scanning or external signature proof.
4 credits per call · $0.04 USDC with x402
Sample input
{
"tools": [
{
"name": "search_docs",
"description": "Retrieve documentation",
"inputSchema": {
"type": "object",
"properties": {
"q": {
"type": "string"
}
}
},
"annotations": {
"readOnlyHint": true
}
},
{
"name": "execute_shell",
"description": "Run shell command on the agent host",
"inputSchema": {
"type": "object"
},
"annotations": {
"readOnlyHint": true
}
}
],
"policy": {
"allow_tools": [
"search_docs"
]
}
}Worked sample output
{
"ok": true,
"mode": "mcp-tool-surface-audit",
"evaluated_tools": 2,
"outcome": "manual_review",
"metadata_risk_score": 62,
"findings": [
{
"tool": "execute_shell",
"severity": "high",
"reason": "potential_side_effect",
"categories": [
"exec"
],
"index": 1
},
{
"tool": "execute_shell",
"severity": "critical",
"reason": "conflicting_read_only_annotation",
"index": 1
},
{
"tool": "execute_shell",
"severity": "medium",
"reason": "tool_not_in_caller_allowlist",
"index": 1
}
],
"counts": {
"critical": 1,
"high": 1,
"medium": 1
},
"inventory_sha256": "267d493d115327ef684f5515ca6c3e6a6bdd85c6cc28c00f0d0e44592c04a216",
"assumptions": [
"Only caller-provided tool declarations were inspected; no MCP server was contacted.",
"Keyword signals are static heuristics, not a vulnerability scan or a tool-behavior guarantee.",
"Tool descriptions and readOnly annotations may be inaccurate; enforce authorization outside this report."
],
"charged_downstream": false,
"server_called": false
}Worked example using published sample data only. Own-data execution is paid.
Connect in curl
Set BOUNTY_API_KEY privately after your payment is verified. Change the retry key for each new logical request.
curl 'https://bounty-engineer-x402-prod.onrender.com/v1/prepaid/mcp-tool-surface-audit' \
-H "Authorization: Bearer $BOUNTY_API_KEY" \
-H 'Content-Type: application/json' \
-H 'Idempotency-Key: workflow-request-001' \
-H 'X-Max-Credits: 4' \
--data '{"tools":[{"name":"search_docs","description":"Retrieve documentation","inputSchema":{"type":"object","properties":{"q":{"type":"string"}}},"annotations":{"readOnlyHint":true}},{"name":"execute_shell","description":"Run shell command on the agent host","inputSchema":{"type":"object"},"annotations":{"readOnlyHint":true}}],"policy":{"allow_tools":["search_docs"]}}'Connect in n8n
Download the inactive n8n template. Import it, configure the private Header Auth credential, inspect the sample and run it manually. A new execution creates a new billable request; there is no automatic schedule.
Use an HTTP POST to https://bounty-engineer-x402-prod.onrender.com/v1/prepaid/mcp-tool-surface-audit. Send JSON and these headers; store the Bearer token as a private credential.
{
"method": "POST",
"headers": {
"Authorization": "Bearer YOUR_PRIVATE_API_KEY",
"Content-Type": "application/json",
"Idempotency-Key": "UNIQUE_PER_LOGICAL_REQUEST",
"X-Max-Credits": "4"
},
"body": {
"tools": [
{
"name": "search_docs",
"description": "Retrieve documentation",
"inputSchema": {
"type": "object",
"properties": {
"q": {
"type": "string"
}
}
},
"annotations": {
"readOnlyHint": true
}
},
{
"name": "execute_shell",
"description": "Run shell command on the agent host",
"inputSchema": {
"type": "object"
},
"annotations": {
"readOnlyHint": true
}
}
],
"policy": {
"allow_tools": [
"search_docs"
]
}
}
}Reuse a retry key only for the same input. Failed execution returns reserved credits. Full integration and recovery guide · Machine-readable recipe