OWASP MCP Taxonomy
概览
Open, vendor-neutral classification of MCP security risks, weaknesses, attack patterns, controls, detections, and test cases for the Model Context Protocol ecosystem. It is a single, combined document covering glossary, design principles, taxonomy structure, framework mappings, CVE-aligned tags, and external crosswalks. Maintained and curated by Vandana Verma Sehgal The combined document includes, in order: 1. — host, client, server, transport, and backend boundaries 2. — taxonomy patterns, 11-domain model, entry quality bar, anti-patterns 3. — MCP terms, AI security terms, and AppSec terms used across MCP security 4. — host vs client vs server, tool vs resource vs prompt, injection families, CVE vs CWE vs CVSS vs EPSS 5. — legacy 7-domain grouping for high-level risk navigation 6. — MCP01–MCP10 with examples, impacts, and controls 7. — CVE-aligned tags such as INJ-CMD, PATH-TRAV, SSRF, AUTH-BYPASS, X-TENANT 8.
README
MCP Security Taxonomy
A common language for securing agentic AI connections, context, and capability.
Open, vendor-neutral classification of MCP security risks, weaknesses, attack patterns, controls, detections, and test cases for the Model Context Protocol ecosystem.
Start with the complete reference:
MCP-SECURITY-TAXONOMY-COMPLETE.md
It is a single, combined document covering glossary, design principles, taxonomy structure, framework mappings, CVE-aligned tags, and external crosswalks.
Maintained and curated by Vandana Verma Sehgal
Complete reference (sections)
The combined document includes, in order:
- MCP relationship map — host, client, server, transport, and backend boundaries
- Design principles — taxonomy patterns, 11-domain model, entry quality bar, anti-patterns
- Glossary — MCP terms, AI security terms, and AppSec terms used across MCP security
- Common confusions — host vs client vs server, tool vs resource vs prompt, injection families, CVE vs CWE vs CVSS vs EPSS
- Taxonomy overview — legacy 7-domain grouping for high-level risk navigation
- OWASP MCP Top 10 mapping — MCP01–MCP10 with examples, impacts, and controls
- Root cause (weakness family) taxonomy — CVE-aligned tags such as
INJ-CMD,PATH-TRAV,SSRF,AUTH-BYPASS,X-TENANT - External references — MCP-38, MCPShield, MCPSecBench, MCP-DPT, community standards, and practitioner guides
Who this is for
- Security engineers threat-modeling MCP hosts, clients, servers, and gateways
- Developers building or integrating MCP servers and tools
- GRC and compliance teams mapping MCP risks to OWASP, CWE, NIST CSF, ISO 27001, and related frameworks
- Researchers comparing MCP taxonomies (MCP-38, MCPShield, MCPSecBench, MCP-DPT)
安装
This server does not publish a one-line install command.
Open the repository installation guide