Audit the authority, not just the package.
An MCP server can expose filesystem, shell, browser, database, cloud, email, payment or deployment authority to an AI agent. A useful audit therefore asks more than whether dependencies have CVEs: it maps what tools are exposed, which identity they inherit, what targets they can reach, and which state-changing consequences are actually possible.
What FOXIFY checks
- Tool inventory and read-vs-write authority.
- Credential, account, project, tenant and session scope.
- Filesystem, shell, browser, database, network and payment sinks.
- Approval, refusal, destination and intent-binding boundaries.
- Replay, retry and ambiguous-outcome behavior around consequential actions.
- Evidence needed to reconstruct one action after the fact.
Start free
Run the open-source Agent Authority Check against a repository. Static observations are not treated as vulnerabilities until reachability and consequence are established.
Need a bounded result?
99-Star Quick Check is the low-friction entry for one public GitHub repository at the current 99-Star launch price. For deeper human verification, the Authority Review starts at $500 for one bounded MCP/agent surface.