Back to the registry
Agent passport

MCP Server Security and Governance Assessment

Bonis Systems · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach3 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownProfessional service
ProvenanceUnknown33% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

Teams are shipping Model Context Protocol servers faster than they can review them. A tool definition is a published instruction set. An endpoint without authentication is a public one. Most MCP surfaces expose both, and the exposure is usually discovered by someone outside the organization. This assessment examines one MCP server or agent API surface of up to 10 tool endpoints and returns a written report. It covers five areas: authentication and authorization posture, including what is reachable without credentials; tool-definition exposure, and what published schemas reveal about internal systems; input validation and fail-closed behavior under malformed or hostile input; prompt-injection surface, where untrusted content reaches an instruction path; and provenance and audit-trail integrity, meaning whether you can demonstrate after the fact what an agent actually did. Each finding states the observed behavior, why it matters, and a specific remediation. Findings are ranked by exploitability rather than by scanner severity. One re-test of remediated findings is included within 30 days of delivery. This assessment relates to MCP servers and agent APIs deployed on AWS services, including Amazon Bedrock and Amazon Bedrock AgentCore, AWS Lambda, Amazon API Gateway, Amazon ECS, AWS Fargate, and Amazon EKS. It also applies to AI agent and tool products listed in AWS Marketplace, whose sellers must be able to describe their own security posture. Bonis Systems LLC is a Wyoming company operating MCP endpoints in production under continuous third-party probing, on infrastructure built around fail-closed gating, hash-chained event records, and post-quantum signatures. This assessment applies that operating experience to your surface.

Highlights

Highlighted by the publisher on AWS Marketplace.

Fixed scope and fixed price. One MCP or agent API surface, up to 10 tool endpoints, written report within 10 business days of scope confirmation. No hourly billing and no open-ended engagement.

Five areas examined: authentication posture, tool-definition exposure, input validation and fail-closed behavior, prompt-injection surface, and audit-trail integrity. Findings are ranked by exploitability, not by scanner severity.

Every finding names the observed behavior, why it matters, and a specific remediation. One re-test of remediated findings is included within 30 days, so the engagement ends with the fix confirmed rather than with a report.

Preview

1 image
MCP Server Security and Governance Assessment preview 1

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Unknown
Not stated
Delivery
Professional service
Support is provided by email at fields@bonissystems.com. Inquiries received before or during an engagement are answered within two business days. Scope questions, clarification of any finding, and guidance on interpreting the report are included at no additional cost for the life of the engagement. Each purchase includes one re-test of remediated findings, requested by email within 30 days of report delivery. Bonis Systems LLC, Wyoming. Web: https://bonissystems.com
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.