CuratedMCP

Fixed fee · one week · nothing to procure

Find out what your AI coding tools can actually reach.

Your engineers installed MCP servers into Claude Code, Cursor, and Copilot to move faster. Nobody kept a list. We produce that list — risk-graded, with a remediation plan — in one week, for a flat fee.

No software to buy, no agent to roll out, no procurement cycle. Or scan one machine free to see the shape of it first.

From our own catalog review

MCP servers are not read-only tools.

We've read the source of 73 MCP servers before listing them. This is what that review found — and it's the same review we run against whatever is on your machines.

1 of 73

servers we reviewed is read-only

Every other one can write, fetch, reach the network, or run commands.

74%

require a secret in a config file

52 of the 70 servers that publish a config example ask for a key, token, or password in plaintext.

10

can execute shell commands

Roughly one in seven. Most developers installing them don't check.

Source: the CuratedMCP catalog, 73 approved servers, each reviewed by hand. Read the full analysis

What you get

Written findings report

Every MCP server found across every AI client on every machine in scope — risk-graded, with credential exposure, network egress, and shell-execution flags called out per server.

Prioritized remediation list

What to remove, what to pin to a version, what to allowlist. Ordered by actual risk, not by alphabet — so your team knows what to do Monday morning.

Starter allowlist config

A ready-to-adopt policy file covering the servers you keep, so the same sprawl doesn't reappear next quarter.

60-minute findings review

A working session with your engineering or security lead to walk the findings and agree the remediation order. Not a sales call.

How it works

  1. 01

    You run one command per machine

    Each developer runs it once. It takes about 60 seconds and needs no admin rights.

    npx curatedmcp login <token>
    npx curatedmcp audit --sync
  2. 02

    We analyse the fleet

    Results aggregate into a single inventory across every machine and every AI client. We review each finding by hand — the tooling collects, a human interprets.

  3. 03

    You get the report and the review call

    Findings, remediation order, and the allowlist config. Yours to keep whether or not you ever buy anything else.

What leaves the machine: server names and risk flags only — never commands, arguments, environment variables, or file paths. The scanner is open source and MIT-licensed, so your security team can read exactly what it sends before anyone runs it.

Fixed price. No surprises.

Quoted up front and invoiced once. Most teams expense this without a procurement cycle.

Team

$2,500

flat, one engagement

  • Up to 10 developer machines
  • 5 business days
  • All four deliverables
  • 60-minute findings review

Org

$5,000

flat, one engagement

  • Up to 50 developer machines
  • 10 business days
  • All four deliverables
  • Findings review with security + engineering

Want this watched continuously instead of once? The assessment is a point-in-time snapshot. Teams that want the inventory kept current move to the Control Plane at $29/seat. Larger rollouts with SSO, SIEM export, and a self-hosted option run through the 60-day pilot. Neither is required — the assessment stands on its own.

Book a 20-minute scoping call

Tell us roughly how many machines and which AI tools your team uses. We'll confirm scope, price, and a start date. If an assessment isn't the right fit, we'll say so on the call.

We respond within one business day. No sales pressure, no spam.