TKOResearch
Menu

MCP & Tool-Use Blast-Radius Review

Independent MCP security review for teams connecting LLMs to real tools.

A technical review of Model Context Protocol servers, clients, tools, tokens, and approval paths before broad rollout.

Best fit

Platform, security, developer experience, and AI infrastructure teams adopting MCP or custom tool-use gateways.

Use this when LLM clients are being connected to internal systems, SaaS tools, file stores, ticketing systems, databases, or deployment workflows.

Review focus

TKOResearch identifies where tool calls cross trust boundaries, where permissions exceed intent, and where containment controls need clearer engineering controls.

What you get

Decision support for connected AI systems.

Within 10 business days, you receive: threat model, agent/tool attack-path map, RAG isolation findings, MCP/API permission matrix, sanitized transcripts where applicable, prioritized mitigations, and an executive Go/No-Go memo.

Sample assessment package

Every engagement produces a decision-ready assessment package: an executive Go/No-Go memo, technical findings register, architecture/trust-boundary review, abuse-case matrix, and prioritized remediation roadmap.

Tool Inventory Matrix

Inventory of MCP servers, tools, permissions, OAuth scopes, credentials, data touched, and allowed actions.

MCP Trust-Boundary Review

Analysis of MCP client/server trust, upstream APIs, token flow, session handling, and local-server exposure.

Destructive-Action Control Plan

Classification of high-impact actions and required approval, policy, sandboxing, or hard-deny controls.

Blast-Radius Map

Clear explanation of what an abused agent/tool path can read, write, modify, delete, send, execute, or deploy.

Scope Reduction Plan

Practical roadmap for least privilege, allowlists, user-scoped auth, egress limits, and tool-call logging.

Risk addressed

Tool, data, and trust-boundary risk in one review.

  • Focused on real tool execution paths rather than generic LLM policy language
  • Suitable for internal platforms, customer-facing integrations, and vendor review preparation
  • Balances permission reduction with the workflow utility teams need to preserve

When to use it

Principal-led, architecture-level review for high-stakes agent deployments.

Use this when a specific system boundary needs senior technical judgment before production access, customer review, or executive approval.

Written scope

Request a scoped review before granting broader system access.

Request written scope