OWASP MCP Mapping
See how MCP Shield findings map to MCP security categories such as tool poisoning, command injection, scope creep, and telemetry gaps.
MCP01
Secrets / Credential Exposure
Hardcoded API keys or tokens in tool metadata
MCP02
Scope Creep
Permissions exceed the tool’s stated purpose
MCP03
Tool Poisoning / Prompt Injection
Hidden instructions inside tool descriptions
MCP04
Tool Shadowing
Suspicious tools mimicking legitimate names
MCP05
Command Injection Risk
Exec/shell capabilities with unsafe description patterns
Mappings are generated from real detector outputs during scan. Categories shown here reflect the project’s documented sample ground truth and rule families — not external unverified claims.