Legal

Acceptable Use Policy

mcpgawk is a defensive security tool. This policy sets the one rule that matters most: only test what you are allowed to test.

Authorised targets only. You may use mcpgawk only against MCP servers and systems that you own, or that you have explicit permission from the owner to test. If you are not sure you are allowed to test a system, you are not allowed to test it.

What mcpgawk is for

mcpgawk is built to help you understand and defend your own Model Context Protocol servers: measuring their cost and exposure, verifying their behaviour in a sandbox, enforcing policy on live traffic, and monitoring them for drift. It is a defensive and diagnostic tool, intended for use by the owner of a server or by someone the owner has authorised to test it.

Authorised use

You may use mcpgawk to test, scan, verify, enforce policy on, and monitor:

  • MCP servers and systems that you own or operate; and
  • MCP servers and systems that you have been explicitly authorised in writing by the owner to test (for example, as part of an engagement or an internal security review).

Prohibited use

You must not use mcpgawk, or any part of the Service, to:

  • scan, probe, attack, or attempt to gain access to any system you do not own and are not explicitly authorised to test;
  • break any law, including computer-misuse, unauthorised-access, hacking, wiretapping, or data-protection laws in any jurisdiction that applies to you or the target;
  • develop, deliver, or improve malware, exploits, or attack infrastructure intended to harm systems you are not authorised to test;
  • exfiltrate, intercept, or misuse data belonging to others;
  • disrupt, overload, or degrade any system or network you are not authorised to test;
  • circumvent, share, or resell licence keys, or otherwise breach the Terms of Service;
  • misrepresent mcpgawk's output, for example presenting a result as a guarantee of safety when it is not.

Your responsibility

You are solely responsible for how you use mcpgawk and for ensuring you have the authority to test any system you point it at. Running a security tool against systems without permission can be a criminal offence. We provide the tool; the decision of where and how to use it, and the legal responsibility for that decision, are yours.

Enforcement

If we reasonably believe you have breached this policy, we may suspend or terminate your access and disable your licence key, with or without notice, and we may report unlawful activity to the relevant authorities. We are not liable for any loss arising from your misuse of mcpgawk, and you agree to indemnify us in the circumstances set out in the Terms of Service.

Reporting misuse or vulnerabilities

If you become aware of someone misusing mcpgawk, or you find a security issue in mcpgawk itself, please tell us at hello@nativerse-ventures.com. Responsible disclosure is welcome; see our security policy.

Contact

Nativerse Ventures Ltd, Flat 27, Pechiney House, The Grove, Slough, SL1 1QP, United Kingdom  ·  hello@nativerse-ventures.com