Organize evidence for one MCP workflow, identify unresolved checks, and copy a review without private notes. This operator register records your assessment; it does not inspect a deployment or issue a security verdict.
Remove secrets and personal data before typing or pasting. Statuses and notes stay in this tab’s memory; the tool does not transmit, log, or save them. It does not connect to your systems or verify controls.
Use Pass when you have supporting evidence, Fail for a known gap, and Unknown when evidence is missing or applicability is unresolved. For a conditional question, record the applicability decision and owner in your own controlled register. Notes are optional: at most 500 Unicode characters each and 10,000 total. An excessive edit is rejected in full and the previous note is kept.
Choose a specific workflow, acting identity, client and server versions, transport, and set of destination permissions. Keep evidence links, owners, dates and decisions in your organization’s controlled register. This temporary browser worksheet does not save that record. Use synthetic or sanitized notes here; do not paste access tokens, customer content, credentials or incident evidence.
For example, an operator reviewing a fictional document-summary workflow might mark destination write restrictions Unknown until a denied-write test is available. A known overbroad grant belongs under Fail. A Pass should point to evidence in the controlled register, not merely to a tool’s description. The example describes a review method, not a performed test.
References beside the questions identify relevant guidance. MCP’s 2026-07-28 security material informs the local-execution, credential, authorization-URL, destination and state-handle checks. Its tools specification informs catalog-change review and the treatment of annotations as untrusted hints. OWASP LLM06:2025 informs capability restriction, permission enforcement, human approval and activity monitoring.
The evidence prompts, ownership questions, suspension rehearsal and recovery steps are our operational recommendations derived from those concerns. They are not a verbatim official checklist or new protocol requirements. Source mappings provide a starting point for review, not comprehensive coverage of each threat. Apply your own threat model and security review to the actual deployment.
For local or stdio use, examine the launched process and its access to files, environment variables, the network and any privileged proxy. A local transport does not make the executable trustworthy or isolate its permissions. For protected HTTP services using MCP authorization, test the applicable identity, token audience, consent and redirect requirements; do not impose that HTTP flow on every stdio server.
Server-provided discovery metadata and URLs cross a trust boundary. Review destination restrictions for the environment, including redirects and changing DNS answers. Separately inspect how a client renders metadata and opens authorization URLs. This page never fetches those URLs, probes a network or attempts an exploit.
MCP 2026-07-28 is stateless at the protocol level. Application workflow handles can still span requests and need appropriate ownership checks; possession of a handle is not authentication. Session-ID guidance for 2025-11-25 and earlier is a separate legacy concern, not a universal current-protocol requirement.
For Fail, assign the gap to an owner and test the proposed correction. For Unknown, first resolve applicability and collect evidence. Retain the test conditions and limitations even when you select Pass. A failing low-impact check and a failing high-impact check are not equivalent risks, so this tool does not average them into a score.
Use these fictional review-meeting cases to turn a status into assigned work. Owner, evidence and decision cells stay blank here: fill them in your organization’s controlled register, not in this static example.
| Review case | Next step | Owner | Evidence reference | Decision |
|---|---|---|---|---|
| Known overbroad downstream permission — Fail | Assign the permission owner to narrow the grant. Collect denied-write evidence using an authorized synthetic fixture before reassessing the restriction. | |||
| Suspension has not been tested — Unknown | Assign an exercise owner and name a suspension exercise with a synthetic workflow. Record what should stop, what actually stops and any in-flight work still requiring reconciliation. | |||
| HTTP-only question in a stdio-only workflow — applicability unresolved | Have the review owner confirm transport scope and retain the applicability decision and rationale in the external register. Keep Unknown while that decision is unresolved; absence of HTTP is not evidence that an HTTP control passed. |
The three worksheet statuses cannot encode every applicability or exception decision. Preserve those decisions separately, including their scope and conditions; the copied agenda is not deployment approval.
Use the note-free copy as a discussion agenda. It deliberately omits every free-text note and cannot replace your evidence register. Changing any answer removes the old review; an oversized edit is rejected in full while preserving the prior note. Clipboard denial exposes the same note-free receipt for manual copying. Resetting the tab cannot remove a copy already on your clipboard.
No. These are operator-selected questions informed by MCP and OWASP guidance, not an official certification checklist. Statuses are self-reported, and the tool verifies no controls. Even all Pass establishes neither security, readiness nor compliance.
Use Pass when supporting evidence exists, Fail for a known gap, and Unknown when evidence or applicability is unresolved. Resolve conditional transport and deployment questions with the responsible owner in your own controlled register. Counts are not a risk score.
No. Local and stdio servers need process, file, environment and launch-permission review. Protected HTTP and OAuth deployments have their own applicable authorization, token and destination requirements. The questions identify those conditions; this tool does not test either transport.
Only fixed questions, selected statuses and fixed next steps. Every free-text note is omitted entirely; the tool does not try to detect arbitrary secrets. Inspect anything you add before sharing. A copied receipt is not a complete evidence record or a configuration file.
Notes and statuses remain in this tab's memory. The tool does not send, log, persist or add them to a URL. Each note allows 500 Unicode characters and the total allows 10,000; excess edits are rejected without truncation. Clear all resets everything in the tab, and reload starts with Unknown and empty notes. An existing clipboard copy cannot be erased by Clear all.