AgentReadyHomeAgent Listing
Home · AI Security Answers · Agentic AI threats & frameworks

What is the OWASP Top 10 for MCP (Model Context Protocol)?

Grounded & cited · AI agent security

The OWASP MCP Top 10 is an official OWASP project (version v0.1 / 2025 IDs, in Beta — Phase 3 Pilot Testing) cataloging the ten most critical security risks specific to deployments of the Model Context Protocol (MCP) — the open standard agents and LLMs use to call external tools, data sources, and services. The risks span secret and token mismanagement, scope creep, tool poisoning, supply-chain tampering, command and prompt injection, weak auth, missing audit, shadow servers, and context over-sharing.

Where MCP sits in the agentic stack

MCP01:2025 — Token Mismanagement & Secret Exposure

MCP02:2025 — Privilege Escalation via Scope Creep

MCP03:2025 — Tool Poisoning

MCP04:2025 — Software Supply Chain Attacks & Dependency Tampering

MCP05:2025 — Command Injection & Execution

MCP06:2025 — Intent Flow Subversion (Prompt Injection via Contextual Payloads)

MCP07:2025 — Insufficient Authentication & Authorization

MCP08:2025 — Lack of Audit and Telemetry

MCP09:2025 — Shadow MCP Servers

MCP10:2025 — Context Injection & Over-Sharing

Relation to LLM06 Excessive Agency and agentic tool misuse

MCP-server hardening checklist

Grounded in

How does your AI agent score?

Get a free, instant AI agent security readiness snapshot — mapped to NIST, OWASP & ISO — then unlock the full report with a prioritized, cited fix-list.

Get the AI Security & Compliance Brief
Grounded, practical guidance for securing AI agents — mapped to NIST, OWASP & ISO. Occasional, and you can unsubscribe anytime.

This AI-generated answer is for guidance only — not a certification, audit, or penetration test. Grounded in the NIST AI RMF, OWASP LLM Top 10, and ISO/IEC 42001 control text; verify applicability to your environment.