Good MCP prompts state the objective, permitted tools, authorized scope, and required output. They do not assume that a passive lookup performs a live scan or that the model can schedule work by itself.

Verify the connection

Domain inventory

Host and technology review

Vulnerability prioritization

SOC IP enrichment

Attack-surface drift

Brand impersonation triage

OEM scan and status

Replace the target variable only with an asset you own or are explicitly authorized to test.

OEM tenant usage reconciliation

Search and fetch research

Prompt anti-patterns