OWASP MCP Mapping

See how MCP Shield findings map to MCP security categories such as tool poisoning, command injection, scope creep, and telemetry gaps.

MCP01

Secrets / Credential Exposure

Hardcoded API keys or tokens in tool metadata

MCP02

Scope Creep

Permissions exceed the tool’s stated purpose

MCP03

Tool Poisoning / Prompt Injection

Hidden instructions inside tool descriptions

MCP04

Tool Shadowing

Suspicious tools mimicking legitimate names

MCP05

Command Injection Risk

Exec/shell capabilities with unsafe description patterns

Mappings are generated from real detector outputs during scan. Categories shown here reflect the project’s documented sample ground truth and rule families — not external unverified claims.

Back to Home