Security work that begins with authority, not assumptions.
FOXIFY reviews AI-agent and MCP systems by binding the acting identity, available tools, reachable targets, state-changing consequences, approval boundaries, retry behavior, and the evidence needed to verify the final outcome.
Choose the smallest useful lane
- Free Authority Preview: one public GitHub repository, bounded source observation, no credentials and no active testing.
- Quick Check: one public repository with a deterministic authority map and evidence-oriented findings.
- Scoped Human Review: one production-facing or explicitly authorized agent/MCP boundary that needs deeper judgment, retest, or remediation guidance.
- Change Monitor: recurring review only after the monitored target and reporting boundary are agreed.
What a scoped review covers
- Identity, credential, account, tenant, project, wallet, and session scope.
- Tools, operations, destinations, and exact state-changing targets.
- Approval, refusal, destination, parameter, and intent-binding controls.
- Replay, retry, idempotency, and ambiguous-outcome handling.
- Authoritative postconditions, audit reconstruction, and recovery evidence.
Authorization boundary
Public-source work stays public-source. Active testing begins only after ownership or explicit authorization and an exact scope are established. Do not submit passwords, private keys, API keys, private repository credentials, production customer data, or seed phrases.
What the review delivers
A review produces a bounded authority map, the evidence behind each material finding, explicit unknowns, and a prioritized remediation path. When changes are applied, the retest checks the same consequence boundary again instead of assuming that a configuration change fixed the outcome.
Success means the system can explain who may act, on which target, with which limits, what must be approved, how retries are controlled, and which authoritative readback proves completion. If any of those facts remain unknown, FOXIFY reports the uncertainty rather than upgrading it into a security claim.
Start
Run the free public-repository preview →
Email contact@foxify.pro with the company/product name and public target URL →