Overview
What the assessment covers
The five areas examined in an MCP server security assessment: authentication posture, tool-definition exposure, input validation, prompt-injection surface, and audit-trail integrity.
Teams are shipping Model Context Protocol servers faster than they can review them. A tool definition is a published instruction set. An endpoint without authentication is a public one. Most MCP surfaces expose both, and the exposure is usually discovered by someone outside the organization. This assessment examines one MCP server or agent API surface of up to 10 tool endpoints and returns a written report. It covers five areas: authentication and authorization posture, including what is reachable without credentials; tool-definition exposure, and what published schemas reveal about internal systems; input validation and fail-closed behavior under malformed or hostile input; prompt-injection surface, where untrusted content reaches an instruction path; and provenance and audit-trail integrity, meaning whether you can demonstrate after the fact what an agent actually did. Each finding states the observed behavior, why it matters, and a specific remediation. Findings are ranked by exploitability rather than by scanner severity. One re-test of remediated findings is included within 30 days of delivery. This assessment relates to MCP servers and agent APIs deployed on AWS services, including Amazon Bedrock and Amazon Bedrock AgentCore, AWS Lambda, Amazon API Gateway, Amazon ECS, AWS Fargate, and Amazon EKS. It also applies to AI agent and tool products listed in AWS Marketplace, whose sellers must be able to describe their own security posture. Bonis Systems LLC is a Wyoming company operating MCP endpoints in production under continuous third-party probing, on infrastructure built around fail-closed gating, hash-chained event records, and post-quantum signatures. This assessment applies that operating experience to your surface.
Highlights
- Fixed scope and fixed price. One MCP or agent API surface, up to 10 tool endpoints, written report within 10 business days of scope confirmation. No hourly billing and no open-ended engagement.
- Five areas examined: authentication posture, tool-definition exposure, input validation and fail-closed behavior, prompt-injection surface, and audit-trail integrity. Findings are ranked by exploitability, not by scanner severity.
- Every finding names the observed behavior, why it matters, and a specific remediation. One re-test of remediated findings is included within 30 days, so the engagement ends with the fix confirmed rather than with a report.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Support
Vendor support
Support is provided by email at fields@bonissystems.com .
Inquiries received before or during an engagement are answered within two business days. Scope questions, clarification of any finding, and guidance on interpreting the report are included at no additional cost for the life of the engagement.
Each purchase includes one re-test of remediated findings, requested by email within 30 days of report delivery.Bonis Systems LLC, Wyoming. Web: