FHI MCP Server Security Audit
Free payment guide and Base-USDC x402 MCP security, package, domain, and SEC tools.
- 1.4.0
- Version
- remote
- Transport
- 7
- Tools
Security review
Review passedReviewed 1d ago.
- tools: 7 tools scanned
- metadata: scanned
No findings.
Tools (7)
payment_info
Free guide to the FHI MCP tools, Base-USDC x402 payment flow, and per-tool prices.
domain_change_evidence
Stateful DNS, CAA, and certificate-transparency monitoring for a public domain. The first call establishes a baseline; later calls return evidence changes and certificate-expiry signals. ($0.01 USDC on Base)
package_install_preflight
npm or PyPI install preflight: blocks missing packages, detects near-name typosquats when an expected name is supplied, and checks OSV advisories. ($0.003 USDC on Base)
sec_material_event_delta
New SEC 8-K, 6-K, and late-filing evidence since a cursor date; accepts a ticker or CIK. ($0.01 USDC on Base)
mcp_payment_preflight
MCP server security audit before an agent connects or pays: probes initialize and tools/list, then returns an ALLOW, CAUTION, or BLOCK risk score for command, filesystem, or wallet capabilities; prompt-injection or data-exfiltration signals; permissive JSON-schema inputs; missing HSTS; and a large tool surface. Does not execute tools. ($0.01 USDC on Base)
mcp_change_evidence
Stateful live remote-MCP monitor for tool-rug-pull and tool-poisoning risk. Establishes an endpoint baseline, then detects added or removed tools, altered tool descriptions, risk-score changes, and newly observed high-risk capability signals before an agent reconnects or pays. Unlike a manifest diff, it fetches the live endpoint and retains the prior observation. ($0.003 USDC on Base)
mcp_vendor_due_diligence
One decision-ready due-diligence dossier before an agent adopts or pays an MCP vendor: live MCP metadata and tool-risk preflight, DNS/CAA/certificate evidence, plus optional SEC material-filing evidence for a public company. Does not execute vendor tools or certify safety. ($0.10 USDC on Base)