When a customer’s security review asks that question, this is the document you send back: every capability your
agent holds, what each one can change, and the limits we recommend — dated and written to be read by someone who did not build it.
Who it is for
Teams shipping an AI agent or MCP server that acts inside customer systems, and facing a security review, a procurement
questionnaire or an enterprise deal that turns on it.
What you receive
Every capability your agent declares, enumerated from its tool definitions.
Which of them send, delete or move money, and which declare no cap, no expiry, no way to switch them off and no audit trail.
A recommended limit set for each capability: caps, expiry and where a person should approve.
The basis for every reading — declared by your code, inferred from a name, or assumed — so a reviewer can check it.
A one-page summary written for a non-technical reader.
How it works
You send your tool definitions: a tools/list response, an MCP configuration or function schemas. No access to
production and no integration.
We agree scope, price and timing with you before any work starts.
We run the reading, review every finding by hand, and deliver the report.
Price
From $2,500 for a single agent or MCP server, up to $10,000 for several agents or servers
reviewed together. You get a fixed quote before you pay.
What it is not
It is not a certification, not a penetration test, and not a statement that software is safe or unsafe. It describes what
your agent is permitted to do, as declared, and how to bound it.
Independence
Buying an audit does not change any listing, score or ranking in the public index. If a server you maintain is listed, its
page will carry a disclosure that you are a customer. See Independence.
Request an audit
Prefer email? Write to support@leashkit.com. Media Yard LLC operates the Leash Index.