I built this MCP checklist around a mistake I keep seeing in agent systems: reviewing tools one by one.
That misses what the agent can do after capabilities are combined.
My first pass is simple: draw every path from untrusted input to a sensitive source, then to an execution or outbound sink. Filesystem + network is the obvious example, but Git + shell or browser + credentials can be just as important.
The 24-check review surface is public here:
The dangerous capability in an MCP setup may not belong to any single tool.
A filesystem server can read data.
A network server can send data.
Together, they can create an exfiltration path even if each one looks acceptable in isolation.
That is why MCP reviews need a capability map across servers, not just a checklist per tool.
Zealynx's public MCP security checklist covers that combined surface alongside command execution, context poisoning, credentials, supply chain, SSRF, and audit logging.
Use all 24 checks free: