OWASP MCP Top 10 mapped audit coverage
MCP risk review that turns scanner signals into approval evidence.
MCPScan reviews MCP servers, tools, permissions, tokens, prompts, and audit evidence against the risk themes security teams now recognize: shadow MCP, tool poisoning, excessive scope, token exposure, weak authorization, and missing telemetry.
Why this mapping matters
Security teams need a checklist
MCP usage spreads through IDEs, local configs, SaaS connectors, and internal agent platforms. The audit gives AppSec a consistent review surface.
Scanners are a starting point
Raw scanner output needs validation, prioritization, and business context before a team can decide whether to approve, restrict, or block rollout.
Buyers need proof
The output is a buyer-safe report with evidence, remediation steps, and a clear recommendation that can be shared with internal reviewers.
Coverage Map
| Risk Theme | What MCPScan Reviews | Evidence Produced |
|---|---|---|
| Shadow MCP servers | Known and discovered MCP configs, developer tools, server owners, approval status, and unmanaged instances. | Inventory, owner map, approval gaps, and recommended allowlist or registry actions. |
| Token and secret exposure | Environment variables, config references, credential handling patterns, and unsafe intake or report paths. | Secret exposure findings, safe handoff notes, and remediation steps. |
| Privilege escalation and scope creep | Read, write, delete, deploy, payment, ticketing, incident, and admin-capable tools by identity and environment. | Tool capability risk map, severity ranking, and least-privilege recommendations. |
| Tool poisoning and misleading descriptions | Tool descriptions, prompts, prompt-state assumptions, metadata, and model-facing instruction risk. | Validated findings with affected tools, evidence, business impact, and safer wording. |
| Insufficient authentication and authorization | OAuth, API token, session, consent, user-bound access, and server trust boundaries. | Auth gap summary, boundary notes, and approval or block recommendation. |
| Command, file, and network execution risk | Tools that execute commands, read files, write files, call networks, access metadata services, or mutate systems. | Exploitability context, blast-radius notes, and containment recommendations. |
| Audit and telemetry gaps | Logging, tool-call evidence, approval records, retention, and reviewer visibility. | Audit trail checklist, missing evidence list, and readiness status. |
| Context over-sharing | Tool outputs, prompt context, connected data sources, sensitive documents, and downstream agent access. | Data exposure notes, reporting boundaries, and safer workflow recommendations. |
Best next step
Use the MCP Launch Audit when MCP touches source code, tickets, Slack, docs, databases, cloud actions, customer data, payments, incidents, or production workflows. Use the Exposure Snapshot when the team only needs a first inventory and prioritization pass.