Devadex

MCP Security Hardening Kit — Scanner, Rules, Benchmarks & Hardening Checklist

gumroad   $29.00   by soundsclear
new today

Secure Your MCP Servers Before They Ship Scan • Harden • Validate Your Model Context Protocol Deployments 90% Detection Rate 0% False Positives Offline-First THE PROBLEM MCP Adoption Is Exploding — Security Tooling Isn't You're deploying MCP servers for Claude Code, Cursor, Continue, and custom agents. But are they secure? Tool poisoning — Malicious tool calls chain together to steal data or execute SQL injection OAuth token leakage — Bearer tokens, client secrets, JWTs hardcoded in configs Path traversal — Directory traversal via file tool parameters Command injection — Shell injection via tool arguments Server spoofing — Fake MCP servers, version downgrade attacks Prompt injection via tools — Instructions smuggled through tool args/outputs Config vulnerabilities — No TLS, no auth, debug enabled, secrets in plaintext Transport insecurity — SSE without auth, HTTP without TLS, CORS wildcards 🚨 No consolidated hardening kit existed for MCP — until now. THE SOLUTION A Complete MCP Security Hardening Toolkit 🔍 Scanner CLI Scan files/directories. Output SARIF, HTML, JSON, text. CI/CD ready with --strict flag. 📋 50+ Detection Rules 8 categories: tool poisoning, OAuth, path traversal, command injection, server spoofing, prompt injection, config vulns, transport security. 🧪 15 Attack + Benign Fixtures Real-world MCP attack patterns. Labeled with expected detection. Extensible JSON format. 📊 Benchmark Suite Automated validation: ≥80% detection, ≤5% false positive. Per-category breakdown. JSON reports. 🛡️ Hardening Checklist 15 production defenses: transport, config, tools, runtime. Compliance mapping (SOC2, ISO 27001). 🐳 3 Hardened Docker Templates STDIO, HTTP/SSE, Multi-server Gateway. Non-root, read-only, capability drop, mTLS ready. Validated Benchmarks Automated test suite runs on every change — no guessing. 90% Detection Rate Target: ≥80% ✅ 0% False Positive Rate Target: ≤5% ✅ 1.8ms Avg Scan Time Per file 15 fixtures (10 attacks + 5 benign) • 8 categories • Per-category breakdown in reports Product Previews Preview 1: Attack Flow Preview 2: Scanner CLI Preview 3: Bundle Contents Preview 4: Benchmark Dashboard Preview 5: Hardened Outcome Who This Is For AI Engineers Shipping MCP servers to production who need pre-deployment security validation Platform Teams Operating MCP gateways for Claude Code, Cursor, Continue, custom agents Security Engineers Red teaming LLM apps, CI/CD security gates, compliance evidence Founders/CTOs Due diligence on MCP safety before launch, funding, or enterprise deals What You Get (ZIP Package) scanner/mcp_hardening_scanner.py — Main CLI rules/detection_rules.yaml — 50+ rules rules/HARDENING_CHECKLIST.md — 15 defenses fixtures/attacks/ — 10 labeled attack samples fixtures/benign/ — 5 clean samples benchmarks/runner.py — Auto validation docker/stdio-hardened.yaml — STDIO template docker/http-sse-hardened.yaml — HTTP/SSE template docker/gateway-hardened.yaml — Gateway template previews/ — 5× 16:9 SVGs README.md — Quick start guide LICENSE — MIT License manifest.json — Product metadata ⚠️ Important Disclaimers Educational only — No guarantee against zero-day or novel attack vectors Not a runtime WAF — Runs at build/test time, not as a production proxy Maintenance required — Rules need updates as attack vectors evolve No outcome guarantees — Provides detection workflows, not absolute security MCP SDK versions — Rules tested on MCP SDK 1.x, 2.x compatibility in changelog Simple Pricing Single License €39 Launch week: €29 One developer Lifetime updates Commercial use OK Team License €69 Up to 10 seats Lifetime updates Priority support BEST VALUE Also Available on PromptBase Single-skill agent workflow for instant integration with Claude Code, Cursor, Aider, and other AI coding agents. View on PromptBase → Secure Your MCP Servers Today Join engineers using the kit to ship safer AI agents Get the Hardening Kit →

Get it → soundsclear.gumroad.com

Found on Devadex — the discovery index for independent software the big search engines bury. More from gumroad.

Report this listing