# MCP security review checklist

Praesidia · Version 1.0 · Updated 2026-10-03

Use one copy per MCP server and deployment. Mark a control complete only when
you have supporting evidence. Record exceptions, compensating controls and an
owner for every unresolved item. This checklist is a starting point, not a
certification or a guarantee that a server is safe.

## Review record

- Server and publisher: [fill in]
- Deployment / environment: [fill in]
- Version or immutable artifact reference: [fill in]
- Business use and connected agents: [fill in]
- Data accessed and consequential actions: [fill in]
- Security reviewer and service owner: [fill in]
- Review date and next review: [fill in]
- Decision: [approve / approve with conditions / reject / pending evidence]

## 1. Identity and credentials

- [ ] Each remote connection authenticates; any public read-only exception is documented.
- [ ] The calling agent or application has a distinct identity and accountable owner.
- [ ] Credentials have the minimum upstream permissions and are stored outside prompts and source code.
- [ ] Transport encryption and certificate validation are enabled for remote connections.
- [ ] Rotation, expiry and revocation have been tested in the deployed environment.

Evidence / unresolved gaps / owner: [fill in]

## 2. Tool permissions and consequential actions

- [ ] The approved tool inventory is recorded; new tools require review before use.
- [ ] Each agent can call only the tools required for its workflow.
- [ ] Read, write, external-send, financial and destructive actions are distinguished.
- [ ] Arguments are bounded to approved resources, recipients, paths and amounts.
- [ ] Sensitive actions require explicit approval with a defined scope and expiry.
- [ ] A denied, expired or revoked approval prevents execution; replay and timeout behavior are tested.

Evidence / unresolved gaps / owner: [fill in]

## 3. Publisher and tool integrity

- [ ] Publisher provenance, maintenance history and requested permissions have been reviewed.
- [ ] Versions are pinned; upgrades and dependency changes trigger a review.
- [ ] Tool descriptions and schemas are reviewed as untrusted model input.
- [ ] Changes to descriptions, tool lists or permissions are detected and reapproved.

Evidence / unresolved gaps / owner: [fill in]

## 4. Data and execution boundaries

- [ ] Inputs are validated by the server; model-generated strings are not interpolated into shell commands.
- [ ] Tool results cannot grant permissions or approve subsequent actions.
- [ ] Only the context and credentials needed for the tool are shared with it.
- [ ] Sensitive outputs and untrusted instructions are handled before downstream use.
- [ ] Rate, concurrency, timeout and spend limits are set; retries cannot duplicate consequential actions.

Evidence / unresolved gaps / owner: [fill in]

## 5. Evidence, monitoring and recovery

- [ ] Records identify the caller, tool, authorization decision, timestamps and known execution outcome.
- [ ] Sensitive arguments and outputs are redacted or omitted according to the data policy.
- [ ] Log coverage, retention and integrity checks are tested; any bypass paths are documented.
- [ ] Unknown outcomes remain visible instead of being assumed successful.
- [ ] Alerts reach an owner, and credential revocation or workflow suspension is rehearsed.
- [ ] A recovery test defines when the server can safely be reenabled.

Evidence / unresolved gaps / owner: [fill in]

## Follow-up and sign-off

| Gap / exception | Impact | Required action | Owner | Due date | Evidence |
| --- | --- | --- | --- | --- | --- |
| [fill in] | [fill in] | [fill in] | [fill in] | [fill in] | [fill in] |

- Conditions before approval: [fill in]
- Accepted residual risks and decision owner: [fill in]
- Change triggers for another review: [new tools / new data / wider scope / new version / other]
- Reviewer sign-off: [fill in]

## Reading

- Full guide: https://praesidia.ai/blog/mcp-server-security-checklist
- Tool scoping: https://praesidia.ai/blog/scoping-mcp-tool-permissions
- Server vetting: https://praesidia.ai/blog/mcp-server-vetting-registry-risk
- More templates: https://praesidia.ai/tools

You may copy, edit and share this template within or outside your organization.
