MCP servers, tools and autonomous agents ship faster than anyone reviews them. Senueren's Agent Surface Review is a bounded, fixed-price review of your agent's tool boundary — the gap between what a message says and what your agent is allowed to do.
Fixed checklist: MCP tool authorization, confused-deputy, privilege escalation, secret exposure, token passthrough, SSRF, tool poisoning / malicious tool descriptions, excessive permissions, cross-agent authority, unsafe filesystem access, command execution, data exfiltration, missing auditability, replayability, and authorization-vs-execution mismatch.
Engagements: Focused Review (one MCP server / boundary, 48h, from R2,500); Agent Surface Review (agent + tools + auth seam, 72h, from R6,000); Extended / multi-agent (custom). Consent-first — authorized scope only. Findings are evidence-first with reproductions, and where deterministic policy enforcement fits we recommend Quesen. Proof of our engineering: verified external work.
pip install quesen-sdk # Python
npm i quesen-sdk # JavaScript / TypeScript
pip install quesen-langchain # LangChain
pip install quesen-crewai # CrewAI
pip install quesen-autogen # AutoGen
Free sandbox key (no signup, no card): curl -X POST https://web-production-3df26.up.railway.app/sandbox/keys