Audits an MCP (Model Context Protocol) server — its tool definitions, scopes, and config — for over-permissioning and exfiltration risk before you connect it to an agent, and assigns a 0–8 danger score with evidence. Use when asked to vet, audit, or score the safety of an MCP server, its tools, or its manifest before trusting it. Triggers include "is this MCP server safe", "audit this MCP", "check these tool definitions", "review this MCP config before I connect it", "does this tool over-request permissions".