A hands-on security review for teams shipping AI agents, MCP servers, or Claude/GPT-based tooling into production. I run the same scanning methodology behind mcpscan (22 static rules mapped to the OWASP MCP Top 10:2025, benchmarked against 4 real 2026 CVEs including a CVSS 9.1 RCE), plus a manual review pass a scanner alone cannot do.