# MCP & Agent Tool-Chain Security Assessment

> Scoped per engagement · AI Security · https://cisomarketplace.services/services/mcp-agent-tool-chain-security-assessment

Assess the security of agent tool-chains: MCP servers, tool/function connections, inter-agent communication, and the authz/credential model behind agent actions.

## In scope

- MCP server security review
- Tool/function connection authz
- Inter-agent communication security
- Credential & token scoping for tools
- Supply-chain of agent tools

## Deliverables

- MCP/tool-chain security report
- Authz & credential findings
- Inter-agent comms recommendations
- Hardening guide

## Tiers

### Essential: scoped

Review of 1 agent system with up to 3 MCP servers and up to 15 tool/function connections: server configuration, tool authorization checks and credential/token scoping. Design and configuration review.

Limits: ai systems 1

Includes:
- 1 agent system, up to 3 MCP servers
- Up to 15 tool/function connections
- Tool authz and credential scoping review
- Findings report and hardening guide

Excludes:
- Inter-agent communication review
- Tool supply-chain analysis
- Hands-on abuse testing of tools
- Ongoing monitoring

### Advanced: scoped

Assessment of up to 5 agent systems with up to 10 MCP servers and up to 50 tool connections: authz, credential scoping, inter-agent communication, tool supply chain, and hands-on abuse testing of tool calls.

Limits: ai systems 5

Includes:
- Up to 5 agent systems, up to 10 MCP servers
- Up to 50 tool/function connections
- Inter-agent communication security review
- Supply-chain review of third-party tools
- Hands-on tool-abuse and privilege testing

Excludes:
- Ongoing monitoring of new tools and servers
- Remediation implementation
- Model-level red teaming (jailbreak/safety testing)

### Enterprise: scoped

Continuous agent-supply-chain monitoring

Excludes:
- Remediation implementation
- Model-level red teaming

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=mcp-agent-tool-chain-security-assessment
