New startup ideas · AI for people who run the AI themselves · Skills, not services
startup concept
Provenary
Scan third-party skills and MCP servers before you let them touch your data
A pre-install auditor: it statically and dynamically inspects a skill folder or MCP server for prompt injection payloads, silent network calls, credential access and data exfiltration paths, then issues a signed report and a personal allowlist.
- Software subscription
- Enterprise
- Rides 'MCP donated to the Agentic AI Foundation' on December 9
2
similar startups, last 2 years (2 all-time)
yes
1 matching federal grants and programs
Direction supported by government programs and grants
Test it before you build it
$250 · 4 weeks · 25 prospects
For $250 and 4 weeks, prove that an employee running personal MCP servers at work will pay $99 out of pocket for an audit report their IT team actually accepts.
Riskiest assumption · An employee running personal MCP servers under company policy will pay their own money for a third-party audit report, and their IT team will accept that report, before the skill hosts ship first-party signing.
1Focus group: who and where
A senior engineer, analyst or consultant at a 200 to 2,000 person US company who runs 5 or more personally installed skills and MCP servers at work, and whose IT or security team published an AI tool policy or questioned their setup in the last quarter.
where to find 25 · r/mcp, in the threads where people list their server stacks (the community); Smithery and PulseMCP registries, contacting the authors and reviewers of the most-installed servers (the directories); Show HN and MCP security threads on Hacker News plus a local BSides security meetup (the channels and event).
2Sell first, build later
Before any scanner exists: a manual pre-install audit of up to 10 skills and MCP servers you already run - source review plus sandboxed execution with network logging - delivered as a signed PDF risk report within 7 days, formatted so you can hand it straight to your security team.
the ask · $99 one time per audit; the $39 per month personal scanner is quoted for later, not sold yet
a real yes · A real yes is $99 paid before the audit starts, and a second yes is their IT accepting the report in writing; upvotes, 'IT would love this', and requests for a free sample audit are not yeses.
3Small experiments
The first one attacks the riskiest assumption; each ends with a number that says whether to run the next.
1. Sell a manual stack audit
$250 · 14 days
DM 25 power users found through r/mcp and Smithery. Offer a $99 prepaid audit: they send their list of up to 10 installed skills and MCP servers, the founder reads the source and runs each in a sandboxed VM with network logging, and delivers a signed PDF with a risk grade per item in 7 days. Money first, then the audit.
keep going if · 5 of 25 pitched users pay $99 up front
2. Ban-pressure interviews
$0 · 7 days
Book 12 of the 25 for 20-minute calls, decliners included. Ask what IT has said about personal AI tools, what they would lose if the stack were banned, and what a report would need to contain for their security team to accept it. Founder runs all calls.
keep going if · 8 of 12 report a restriction, policy or ban threat in the past 90 days
3. IT acceptance test
$0 · 10 days
Ask each paying customer to forward the signed report to their IT or security contact and copy the founder, or to reply with IT's written reaction. Follow up once after 5 business days and record the outcome per report.
keep going if · 3 of the first 5 reports get written IT acceptance and the tools stay allowed
4Collect a deposit up front
Tesla took $1,000 refundable reservations for the Model 3 and $100 for the Cybertruck before building either: the deposit is the measurement, not the revenue.
$99
per prospect, refundable
how · A prepaid audit invoiced through card checkout before work begins - this buyer spends personal money on tools already, and paying for the audit itself is a cleaner measurement than a reservation for software that does not exist. set up: Stripe Invoicing ↗
what it reserves · The audit slot in the next 7 days, the signed report, and founding access to the $39 a month scanner at $29 locked for a year when it ships
refund · Fully refunded if the report is not delivered within 7 days, or on request any time before the audit starts.
target · 5 paid audits from 25 pitches within 30 days
Go: build it if
5 paid $99 audits and written IT acceptance on at least 3 of the first 5 reports: build the scanner, because both the buyer and the gatekeeper said yes with something at stake.
Kill: stop if
Fewer than 2 of 25 pay, or 0 of the first 3 delivered reports get IT acceptance: either the fear is not worth $99 or a third-party signature carries no weight, and first-party signing by the skill hosts wins.
5 Scripts to run itoutreach message, landing copy, deposit terms · click to open
outreach message
You're running a stack of personal MCP servers at work, which means unreviewed third-party code sits inside the assistant that touches your files, and IT policies are starting to notice. I'm testing a pre-install auditor; before building it I'm auditing 10 stacks by hand: source review plus sandboxed runs with network logging on up to 10 servers, signed PDF risk report in 7 days, $99, written so your security team can read it. Got 20 minutes this week to walk me through your stack?
landing page
Prove your personal AI stack is clean before IT bans it $99: a hand audit of up to 10 skills and MCP servers, signed risk report in 7 days Book your audit slot and pay today, refunded if we miss the deadline
deposit terms
You pay $99 today for a manual audit of up to 10 skills and MCP servers, delivered as a signed risk report within 7 days. Payment reserves your slot and locks founding scanner pricing at $29 a month for your first year. Full refund if the report is late, or on request before the audit begins.
Would you run this test?
One tap. The yes-share feeds the Demand pillar of this idea's score; nobody sees who answered.
Budgets are out-of-pocket estimates for a team of one to three, US market. Size the deposit to the deal, and check the terms before taking money in a regulated line.
Scorecard
Ranked against every idea in the catalog: trend, demand and 100x potential from the corpus, competition relative to the other ideas. A generated concept has no judges or swipes yet, so its pillars use the data signals only.
55
Idea Score, 0-100 (partial) · raw 34.2 x 1.61
Warm
competition: more crowded than 44% of ideas · headwind x0.78
+1.4
government priorities, secondary (1 matching grants)
Trend
47
Is the wave forming now? 2025-26 entrants vs 2023-24, rounds since 2025, the sector's live-batch direction, the 2026 trend analyst.
- Entrants 2025-26 vs 2023-24 (similar companies)92
- Rounds announced 2025+ in the sector0
- Sector direction (live batch)50
Demand
32
Does anyone want it? YC's current RFS, companies already paid for something similar, the operator judge, founders' yes-rate in decks, readers who would run the test.
- YC asks for it (current RFS: idea / sector)30
- Someone already pays (similar companies, recent / all-time)33
100x potential
50
Can it return a fund? The venture judge (double weight), market-size and moat axes, neighbours still alive, the technologist judge.
- no signal yet, taken as 50
Score = 100 x cbrt(Trend x Demand x 100x) x (1 - 0.5 x crowding) + government bonus (max 5), calibrated so the 95th-percentile idea scores 90 (order never changes). A geometric mean: a weak pillar cannot be papered over. Percentiles are among the 382 ideas in the catalog; the terms matched were scan, third-party, skills, mcp, servers, pre-install, auditor, statically.
The concept in full
- What
- A pre-install auditor: it statically and dynamically inspects a skill folder or MCP server for prompt injection payloads, silent network calls, credential access and data exfiltration paths, then issues a signed report and a personal allowlist. Built for the enterprise power user running personal AI tools under company policy who needs to prove their stack is clean. In the first hour a user drags in the ten skills and servers they already installed and gets a risk grade on each.
- Grounded in (2025-2026 signals)
- 'MCP had 97 million monthly SDK downloads and 10,000 active servers' (December 9, 2025 donation to the Agentic AI Foundation). MIT NANDA's State of AI in Business 2025 (published August 2025): 'more than 40% of knowledge workers use personal AI tools at work, a shadow AI economy.'
- What it rides
- Rides 'MCP donated to the Agentic AI Foundation' on December 9, 2025: with 10,000 active servers and one plug any assistant can take, third-party code now runs inside personal assistants with no vetting layer at all.
- Why now
- 10,000 active MCP servers and 97 million monthly SDK downloads as of December 2025 mean unaudited third-party code is already inside the assistants of the 40% of knowledge workers running personal tools at work; the audit layer does not exist yet.
- Wedge: first customer and entry point
- First customer: one security-conscious daily AI user at a mid-size US company who wants to keep their personal stack without getting it banned. Entry point: a $39 a month personal scanner with shareable reports their IT team will accept; team allowlists come later.
- Closest real companies, as the generator saw them
- Tinfoil (yc X25) verifies inference privacy, not the skill code itself; Cotool (yc X25) sells agents to security operations teams, the opposite buyer. Neither audits what a person installs into their own assistant.
- Main risk
- Skill hosts add first-party signing and sandboxing to the standard fast enough that a third-party auditor never earns trust.
Similar startups in the directory
Companies whose pitch matches most of the concept's terms (scan, third-party, skills, mcp, servers, pre-install, auditor, statically).
Public money in this direction
US federal grants and open opportunities matched to the concept's terms.
National Science Foundation · IUSE · $645K
Other concepts in this collection
- SkillproofRegression testing for the Agent Skills you actually depend on
- LedgerkitVersioned skill packs that make a solo CPA's assistant work like a tax practice
- VendfoldLicensing, signing and auto-update infrastructure for people who sell Agent Skills
- PackroomOne shared skill library for a team where everyone runs their own agent
- TokentabPer-skill cost, routing and drift telemetry for the person who runs AI all day
- ThreadkeepA memory vault you own that every assistant you run can read
- RelayfileHand a running task from Claude Code to Codex without losing state
- MeterhouseOne budget, meter and kill switch for every agent you run
- AttestlyAudit trail and approval inbox for the agents you run at work
- SkillvaneVersion control and regression tests for the skills your agents load
- CrewlineA shared board where each teammate's agents pick up each other's work
- WardkeySecurity scanner that finds and fixes exposed keys in vibe-coded apps
- StillupUptime and error monitoring that answers in fix prompts, not stack traces
- CopystoneAutomatic backups and one-click restore for apps built without engineers
- GroundskeepMonthly maintenance for shipped vibe-coded apps, applied as reviewable patches
- TillhousePayments, sales tax and refunds as one drop-in for non-developer founders
- SpendgateMeter, cap and route the AI spend inside apps vibe coders shipped
- DryloopRehearsal mode for the automations a small business owner builds alone
- MeterlyOne metered key with spend caps for every AI step you run
- FlowmedicWatches your automations, explains failures in plain English, proposes the fix
- ScrubdeckA data-cleaning step any workflow can call, with rules the owner keeps
- OpshandTurns your written SOPs into versioned Agent Skills with tests included
- CrewtraceShared visibility when five people at one business each run their own automations
- VeraciteCitation verification and AI work records for solo attorneys who draft with Claude
- TickstoneTurns a solo CPA's AI sessions into reviewable workpapers with tickmarks and source trails
- ChartproofA verification layer for physicians who use AI on clinical notes under their own license
- CoverlensPolicy-form verification for independent insurance agents who quote with AI
- MethodkitSolo consultants package their methodology as versioned Agent Skills they own and resell
- AttestrailTamper-evident logs of every AI action, built for licensed professionals' liability files
- ScrublineLocal redaction proxy that makes your personal AI accounts safe for work data
- StipendlyTurn personal Claude Max and ChatGPT Pro seats into managed employer stipends
- TollgateA policy gateway between your assistant and every MCP server it touches
- SkillvetScan, pin and approve Agent Skills before they touch company data
- DaylightSelf-serve shadow AI registry and policy for companies with no security team
- LedgerlineRightsizing dashboard for everyone paying for AI out of their own pocket
- SwitchyardOne metered endpoint with routing, fallback and per-person caps for tiny teams
- HearthmeterUsage budgets and one bill for the household that shares AI plans
- SeatcaseMeasures who on your team earns a Max seat and who wastes one
- TokencairnProfiler that shows what each installed skill and MCP server really costs
- FusegateBudget caps, fallback and kill switches for automations you run yourself
- SkillbenchRegression testing for Agent Skills before every model and skill update
- CitelockVerifies every citation in AI-drafted work before a licensed professional signs it
- MiddlegateA local gateway where you set the rules for what your MCP servers can do
- DriftwatchCatches output drift in the automations small operators wired themselves
- ShipcheckPre-launch review gates non-technical builders run on their own vibe-coded apps
- TracelineA claim-level provenance trail for every number in an AI-assisted report
- DrillyardScored practice repos where you learn to drive coding agents well
- PassrateA proctored AI operation exam scored from your real agent transcripts
- PatchcraftDebugging drills that teach non-technical builders to maintain what they vibe coded
- SkillsmithA workshop for writing, testing and versioning Agent Skills that actually hold up
- TickmarkSynthetic client caseloads where CPAs drill AI-assisted work before trying it on real clients
- PostgameAn MCP server that scores your own agent sessions and drills your weakest habits
- CitegridEvery number in your published research links to a source snapshot you verified
- MnemosYour research corpus as a private MCP server every assistant can query
- MeterlineModel routing and cost accounting for one person's AI research pipeline
- SkillcaskVersion, test, and sell your expertise as licensed Agent Skills
- StackfeedA personal data pipeline that repairs itself when sources change
- ClaimboardA shared evidence ledger for small teams where everyone runs their own agent
Fictional concept generated 2026-08-26 by claude-fable-5 from the collection's brief and MarkosWeb data. Treat it as a research prompt, not a plan.