FHI MCP Security Audit

Decision evidence for an AI agent before it connects to, installs, or pays an MCP server. No account and no API key: each paid call uses x402 / Base USDC.

MCP Vendor Due Diligence Dossier — $0.10

One non-executing dossier combines MCP tool-risk preflight, DNS/CAA/certificate evidence, and optional SEC filing evidence. Returns PROCEED, REVIEW, or AVOID with the underlying evidence. It does not certify safety or compliance.

POST /api/v1/mcp-vendor-due-diligence

MCP Server Security Audit — $0.01

Before connecting or paying, inspect MCP metadata and tool declarations for command, filesystem, wallet, prompt-injection, data-exfiltration, schema, HSTS, and tool-surface risks. The audited MCP tools are not executed.

POST /api/v1/mcp-payment-preflight

How an agent buys

  1. Read the machine-readable catalog or connect to /mcp.
  2. Send the normal request. The first paid request returns HTTP 402 with the exact Base-USDC requirement.
  3. Use an x402-capable client to sign and retry the same request. Settlement goes directly to the published pay-to address.

OpenAPI · x402 manifest · LLM guide · MCP discovery card

Evidence tools only; not legal, financial, or security certification.