Threat Catalog
Every detection rule MCPSafe ships. Each entry maps to a CWE and a severity tier, and links to a page with explanation and detection notes. Paste an MCP server on the scan page to run the whole catalog against it.
91 rules · Last updated 2026-05-13T21:12:53Z
| Rule ID | Name | Description | Severity | CWE | Scan type |
|---|---|---|---|---|---|
| MCP-272 | cross-tool-covert-invocation | Closes the Unit42 "Covert Tool Invocation" attack class. A tool's | MEDIUM | CWE-94 | Deep |
| MCP-273 | cors-wildcard-with-credentials | Closes the CORS-misconfiguration honourable mention from the | MEDIUM | CWE-942 | Fast |
| MCP-274 | dns-rebinding-host-validation-missing | Closes a CVE-2025 class of DNS-rebinding attacks against localhost | HIGH | CWE-350 | Deep |
| MCP-275 | oauth-metadata-into-spawn | Closes the CVE-2025-6514 (mcp-remote) class of OS-command injection | HIGH | CWE-78 | Deep |
| MCP-276 | tool-spawn-with-tainted-arg | Closes the CVE-2026-5058 (aws-mcp-server) / CVE-2026-23744 (MCPJam) | HIGH | CWE-78 | Deep |
| MCP-277 | prm-endpoint-missing | Closes the June 2025 MCP Authorization Specification gap: MCP servers | HIGH | CWE-1390 | Deep |
| MCP-278 | pkce-plain-method | Closes the OAuth 2.1 / MCP Authorization Specification PKCE | HIGH | CWE-757 | Deep |
| MCP-279 | resource-indicator-missing | Closes the RFC 8707 / MCP Authorization Specification "Resource | HIGH | CWE-345 | Deep |
| MCP-280 | elicitation-requests-credentials | Closes the MCP Elicitation Specification "MUST NOT request | HIGH | CWE-522 | Deep |
| MCP-281 | elicitation-no-rate-limit | Closes the MCP elicitation spec rate-limit SHOULD requirement. | MEDIUM | CWE-799 | Deep |
| MCP-282 | system-prompt-leakage | Closes the OWASP LLM07 (System Prompt Leakage) gap. Fires when an | MEDIUM | CWE-200 | Deep |
| MCP-283 | auth-without-invocation-log | Closes the OWASP MCP Top 10:2025 MCP08 (Lack of Audit and Telemetry) | MEDIUM | CWE-778 | Fast |
| MCP-284 | destructive-tool-no-audit-event | Closes the OWASP MCP Top 10:2025 MCP08 (Lack of Audit and Telemetry) | MEDIUM | CWE-778 | Fast |
| MCP-285 | context-overshare | Closes the OWASP MCP Top 10:2025 MCP10 (Context Injection & | MEDIUM | CWE-668 | Fast |
| MCP-300 | cascade-prompt-injection | Detects MCP tool handlers that receive unsanitized user input and pass it | HIGH | CWE-94 | Fast |
| MCP-306 | secrets-in-request-logs | Detects logging of sensitive request data (Authorization headers, API keys, | HIGH | CWE-532 | Fast |
Showing 76–91 of 91 rules
MCPSafe detects every issue in this catalog automatically. Paste an MCP server’s GitHub URL or package name on the scan page.
Scan now