The dangerous capability in an MCP setup may not belong to any single tool.
A filesystem server can read data.
A network server can send data.
Together, they can create an exfiltration path even if each one looks acceptable in isolation.
That is why MCP reviews need a capability map across servers, not just a checklist per tool.
Zealynx's public MCP security checklist covers that combined surface alongside command execution, context poisoning, credentials, supply chain, SSRF, and audit logging.
Use all 24 checks free: