FHI MCP Security Audit
Decision evidence for an AI agent before it connects to, installs, or pays an MCP server. No account and no API key: each paid call uses x402 / Base USDC.
MCP Vendor Due Diligence Dossier — $0.10
One non-executing dossier combines MCP tool-risk preflight, DNS/CAA/certificate evidence, and optional SEC filing evidence. Returns PROCEED, REVIEW, or AVOID with the underlying evidence. It does not certify safety or compliance.
POST /api/v1/mcp-vendor-due-diligenceMCP Server Security Audit — $0.01
Before connecting or paying, inspect MCP metadata and tool declarations for command, filesystem, wallet, prompt-injection, data-exfiltration, schema, HSTS, and tool-surface risks. The audited MCP tools are not executed.
POST /api/v1/mcp-payment-preflightHow an agent buys
- Read the machine-readable catalog or connect to /mcp.
- Send the normal request. The first paid request returns HTTP 402 with the exact Base-USDC requirement.
- Use an x402-capable client to sign and retry the same request. Settlement goes directly to the published pay-to address.