Services
Everything published on this site is free, and it stays that way. Every advisory and site notice includes complete remediation guidance you can follow yourself at no cost. For teams that want hands-on help, I also take on a limited amount of paid work.
What I can help with
MCP and AI agent security assessments
A focused review of your MCP servers, AI agents, or AI-assisted tooling before (or after) you ship them. This is the same work behind the advisories published here: transport and authentication weaknesses, DNS rebinding, unsafe tool execution, prompt injection paths, and insecure defaults.
Remediation help for site operators
If you received a notice from me, the For Site Operators page walks through the fix for free, and for most sites that is all you need. If you would rather have someone apply the fix, verify nothing else is exposed, and confirm you are patched, I can do that with you or for you.
Ongoing advisory
Occasional, retainer-style access for teams building in the MCP and AI agent ecosystem who want a security opinion on designs, releases, or incidents as they come up.
How I work
- Published research is never for sale. What gets published here, and when, is independent of any commercial relationship. My process is described in the disclosure policy.
- Notices are not a sales pitch. If I contacted you about your site, that notice was free, the fix on this site is free, and you will never need to pay me to act on it. Paid help exists only for those who prefer it.
- The free guidance is complete. Paid work buys my time, not information that is otherwise withheld.
- Small by design. This is one researcher, not an agency. I take on work I can do well and will say so if something is outside my scope.
Get in touch
Email security@mail.mcpsec.dev with a short description of what you need. I typically reply within a few business days. You can verify this address against the profiles listed on the about page.