TKOResearch
Menu

MCP & Tool-Use Blast-Radius Review

Independent MCP security review for teams connecting LLMs to real tools.

A technical review of Model Context Protocol servers, clients, tools, tokens, and approval paths before broad rollout.

Buyer problem

Your LLM clients are gaining access to real tools, but the team cannot yet show which actions are permitted, which trust boundaries are crossed, or how destructive actions are contained.

Best fit: Platform, security, developer experience, and AI infrastructure teams adopting MCP or custom tool-use gateways.

Scope

MCP clients and servers, tool schemas, OAuth and delegated access, credentials, data flows, read/write/delete/send/execute permissions, approval gates, logging, and rate limits.

Deliverable

A concrete work product tied to the decision.

A tool inventory and trust-boundary review with a permission matrix, destructive-action control plan, blast-radius map, and prioritized scope-reduction roadmap.

Timeline

Typically 10 business days from kickoff and access confirmation.

Signature view / permission lattice

Every tool call should declare its action class.

MCP risk becomes easier to discuss when every tool is classified by what it can do and paired with the control required before that action is allowed.

READ

Can this identity see it?

Retrieve records, files, messages, or system state.

WRITE

Can this identity change it?

Create or modify records, files, configurations, or tickets.

DELETE

Can this action be recovered?

Remove data or resources where recovery may be limited.

SEND

Can this action leave the system?

Communicate externally through email, messaging, publishing, or transactions.

EXECUTE

Can this action alter operations?

Run commands, deploy changes, approve workflows, or alter operations.

Sample assessment package

Agree the review boundary, authorized methods, and decision the work must support before starting. The scoped package draws from the outputs below and identifies untested paths and unresolved assumptions alongside the findings.

Tool Inventory Matrix

Inventory of MCP servers, tools, permissions, OAuth scopes, credentials, data touched, and allowed actions.

MCP Trust-Boundary Review

Analysis of MCP client/server trust, upstream APIs, token flow, session handling, and local-server exposure.

Destructive-Action Control Plan

Classification of high-impact actions and required approval, policy, sandboxing, or hard-deny controls.

Blast-Radius Map

Clear explanation of what an abused agent/tool path can read, write, modify, delete, send, execute, or deploy.

Scope Reduction Plan

Practical roadmap for least privilege, allowlists, user-scoped auth, egress limits, and tool-call logging.

Risk addressed

Tool, data, and trust-boundary risk in one review.

  • Focused on real tool execution paths rather than generic LLM policy language
  • Suitable for internal platforms, customer-facing integrations, and vendor review preparation
  • Balances permission reduction with the workflow utility teams need to preserve

When to use it

Technical review before a consequential decision.

Use this when LLM clients are being connected to internal systems, SaaS tools, file stores, ticketing systems, databases, or deployment workflows.

Next step

Decide whether this is the right review for your next decision.

Request an MCP review