The MCP servers that matter most are the ones nobody can scan.
They're behind your VPN, on a workstation, in a private subnet. Gated audits those — the same way it audits the public ones.
Free first audit. No credit card.
The CLI is a pipe, not a brain.
For a server behind your firewall, you run the gated CLI from inside your network. It dials out and forwards traffic — our scanner drives every probe, and the check logic never leaves our side.
MCP servers ship faster than anyone audits them. A server goes from prototype to mounted-in-production in an afternoon — the review that would catch a leaking tool or a malformed error envelope never happens.
The agent on the other end is an untrusted component with broad tool access. It will call what it is offered. Every tool, resource, and prompt a server exposes is reachable surface, and most of it was never read by a human.
That surface also has a running cost. It is loaded at initialize, counted against the context window every session, and measured by no one. Shipping the server is the cheap part. Everything it quietly does afterward is not.
Gated points two engines at a server and merges what they find into one ranked report — with a reproduction for every finding.
228 deterministic checks
Across security, conformance, quality, reliability, and cost. Each maps to one family and one severity, runs at a chosen intensity, and is identical on every run — the baseline you can put in CI.
An adversarial LLM
An agent that actively tries to break the server — not only to get in, but to surface flaws across all five families. It improvises the attacks a fixed checklist can't, then files them the same way.
See the adversarial phaseFive families. 228 checks.
Every check belongs to one family and runs from a declared intensity upward. How the catalog spreads across the two axes:
| Family | passive | probe | explore | Total | adversarial |
|---|---|---|---|---|---|
| Security | 24 | 44 | 20 | 88 | LLM-driven phase Where the checklist ends, the model begins. It reasons about your target, forms attack hypotheses, and probes them live — surfacing the flaws a fixed catalog never could. |
| Conformance | 34 | 40 | 9 | 83 | |
| Quality | 24 | 1 | 1 | 26 | |
| Reliability | 9 | 3 | 6 | 18 | |
| Cost | 1 | 11 | 1 | 13 | |
| All families | 92 | 99 | 37 | 228 | explainer |
You choose how hard it looks.
Four strictly-ordered levels — each a superset of the one above it, so Explore runs Passive and Probe too. What the server says about itself, then whether it does what it says, then what happens when you use the whole surface for real, then what a determined attacker can extract.
Validates everything the server says about itself — serverInfo, declared capabilities, and the full schemas of every tool, resource, and prompt — without ever making a real tool call. The “lint” intensity: safe on production at any time, safe in CI on every PR.
Starts touching the target, but only safely. Loads resources, calls non-destructive tools, and forces validation failures — negative numbers, out-of-range values, malformed inputs — to see how the server defends its boundaries. No destructive tool is ever called.
Goes all in on legitimate use. Calls every tool with LLM-generated arguments, walks pagination chains, bursts calls to probe rate-limit behavior, and opens many concurrent connections. Best on staging, or production with explicit opt-in.
An LLM-driven attack — prompt injection, tool poisoning, and sustained multi-step exploitation chains, equivalent to a senior tester actively trying to break the server. Requires explicit opt-in per scan.
Three agents, one bounded cage.
At adversarial intensity the work splits across three agents inside one harness. One forms theories from a library of tactics, a second probes the target for each, and a third keeps only what it can prove — every move rate-limited, scoped to a target you own, and on the record.
See a real report before you sign up.
A complete scan of a sample MCP server — the same report you get for your own servers. Browse the ranked findings, the discovered tool surface, and every tool call the scan made. No account required.
Open the demo reportFour tiers. One catalog.
Pick the depth you need.
- Up to 3 targets
- 1 team member (solo workspace)
- 200 scans / month (any intensity)
- 300 inspections / month — hard stop, no overage
- All four intensities, including adversarial
- 30-day scan history
- HTML & PDF reports
- Everything in Free
- Up to 25 targets
- Up to 10 team members
- 1,000 scans / month (any intensity)
- 1,000 inspections / month
- See finding reproduction steps
- 1-year scan history
- SSO
- Everything in Pro
- Up to 100 targets
- Up to 20 team members
- 5,000 scans / month (any intensity)
- 5,000 inspections / month
- Per-scan inspection cap (default 200)
- 2-year scan history SLA
- Everything in Team
- Unlimited team members, targets, scans
- Negotiated inspection bundle (50k–500k / mo)
Straight answers. No fine print.
Missing a question? Email hello@gated.cc — we'd rather answer it directly.
Point Gated at a server.
Public or private, your first audit is free — a ranked report with a reproduction for every finding, in minutes.
Free first audit. No credit card.