I will assess the security of your mcp server or ai tool integration

Sommige informatie wordt in het Engels weergegeven.

Israël

Ik spreek Russisch, Engels, Pools

Senior Application Security Engineer

I am a Senior Application Security Engineer with hands-on ownership of AppSec across multiple products. I specialize in threat modeling, architecture reviews, and manual vulnerability validation. I ha...
Over deze dienst

MCP (Model Context Protocol) servers are the newest, least-audited attack surface in AI right now. Most security tooling for it is still automated-scan-only; it tells you something's exposed but not whether it's actually exploitable.

I do both: discovery scanning to map your attack surface, plus manual exploit validation to prove real impact, not theoretical risk. You get evidenced findings (request/response proof, CWE classification, severity) and concrete remediation steps, not just a list of warnings.

Background: I built and published an open-source MCP security lab demonstrating a full discovery-to-exploit workflow against a real misconfiguration (CWE-22, path traversal), along with code and a write-up, publicly on GitHub, linked in my portfolio.

Note: I test servers/configs you own or have explicit authorization to test. I cannot test third-party or production systems without your confirmation of authorization.

Mijn portfolio