SecureFlow
Check an MCP endpoint
One handshake, the one every MCP client sends, and what it tells a stranger. We call no tools.
Include the path. Most servers mount MCP under /mcp or /sse rather than at the root.
What this handshake does
What we do:
- We sent one MCP initialize request — the handshake every client sends — and read the reply.
- Where that succeeded without a credential, we asked for the tool list and read the names, descriptions and parameter names.
What we do not do:
- We did not call a single tool. Not a read-only one, not a list one, not one that looked safe.
- We did not send a prompt, a payload or a test input to the server.
- We did not attempt any credential, and we did not try a second address or a second path.
What it cannot tell you:
- Whether a tool does what its description says, which needs calling it.
- Whether the systems behind these tools are configured safely, which needs access to them.
- Whether the endpoint resists prompt injection through the content its tools return — a suite of probes that all fail proves only that those probes failed.
- Anything at all about a server that requires a credential, which is most of what we hope to find.
An endpoint that refuses us is an endpoint we can say almost nothing about, and that is the correct result. Connect it to a workspace and it gets the real check.
SecureFlow — a product built by Ruah Tech Solutions, Australia