Fixed fee · one week · nothing to procure
Find out what your AI coding tools can actually reach.
Your engineers installed MCP servers into Claude Code, Cursor, and Copilot to move faster. Nobody kept a list. We produce that list — risk-graded, with a remediation plan — in one week, for a flat fee.
No software to buy, no agent to roll out, no procurement cycle. Or scan one machine free to see the shape of it first.
From our own catalog review
MCP servers are not read-only tools.
We've read the source of 73 MCP servers before listing them. This is what that review found — and it's the same review we run against whatever is on your machines.
1 of 73
servers we reviewed is read-only
Every other one can write, fetch, reach the network, or run commands.
74%
require a secret in a config file
52 of the 70 servers that publish a config example ask for a key, token, or password in plaintext.
10
can execute shell commands
Roughly one in seven. Most developers installing them don't check.
Source: the CuratedMCP catalog, 73 approved servers, each reviewed by hand. Read the full analysis
What you get
Written findings report
Every MCP server found across every AI client on every machine in scope — risk-graded, with credential exposure, network egress, and shell-execution flags called out per server.
Prioritized remediation list
What to remove, what to pin to a version, what to allowlist. Ordered by actual risk, not by alphabet — so your team knows what to do Monday morning.
Starter allowlist config
A ready-to-adopt policy file covering the servers you keep, so the same sprawl doesn't reappear next quarter.
60-minute findings review
A working session with your engineering or security lead to walk the findings and agree the remediation order. Not a sales call.
How it works
- 01
You run one command per machine
Each developer runs it once. It takes about 60 seconds and needs no admin rights.
npx curatedmcp login <token> npx curatedmcp audit --sync - 02
We analyse the fleet
Results aggregate into a single inventory across every machine and every AI client. We review each finding by hand — the tooling collects, a human interprets.
- 03
You get the report and the review call
Findings, remediation order, and the allowlist config. Yours to keep whether or not you ever buy anything else.
What leaves the machine: server names and risk flags only — never commands, arguments, environment variables, or file paths. The scanner is open source and MIT-licensed, so your security team can read exactly what it sends before anyone runs it.
Fixed price. No surprises.
Quoted up front and invoiced once. Most teams expense this without a procurement cycle.
Team
$2,500
flat, one engagement
- Up to 10 developer machines
- 5 business days
- All four deliverables
- 60-minute findings review
Org
$5,000
flat, one engagement
- Up to 50 developer machines
- 10 business days
- All four deliverables
- Findings review with security + engineering
Want this watched continuously instead of once? The assessment is a point-in-time snapshot. Teams that want the inventory kept current move to the Control Plane at $29/seat. Larger rollouts with SSO, SIEM export, and a self-hosted option run through the 60-day pilot. Neither is required — the assessment stands on its own.
Book a 20-minute scoping call
Tell us roughly how many machines and which AI tools your team uses. We'll confirm scope, price, and a start date. If an assessment isn't the right fit, we'll say so on the call.