Pentest an MCP server for authentication bypass, confused-deputy SSRF, and tool-argument injection - black-box from its URL, deeper with repo or host access. Use to assess an MCP server's exposure.