Security auditing and policy gating for MCP servers (local + CI). Deterministic checks. Actionable findings. Reproducible reports.