October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
AI security

OWASP Top 10 for MCP Servers: The 10 Risks and How to Secure Them

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The OWASP Top 10 for Model Context Protocol (MCP) Servers is a living security guide for systems in which an AI application discovers and calls tools supplied by one or more MCP servers. Its ten 2025 risk categories cover secrets, permissions, poisoned tools, dependencies, code execution, prompt and context injection, authentication, telemetry, unmanaged servers, and data oversharing. Use the list as a threat-modeling checklist: inventory every server and tool, minimize credentials and context, validate all inputs and outputs, require approval for dangerous actions, and record enough immutable telemetry to investigate what happened.

What the OWASP MCP Top 10 covers

OWASP labels the current project “OWASP Top 10 for Model Context Protocol version v0.1.” It is intended to evolve with AI-model capability and protocol innovation rather than serve as a permanent, exhaustive standard. OWASP describes it as a living document anchored in real-world threats, research findings and industry feedback.

The architecture is materially different from a conventional web API. A user interacts with an MCP host, such as an AI application. The host runs an MCP client, which connects to one or more MCP servers. Servers expose tools, data and APIs to the model. Local servers commonly communicate over standard input/output (stdio); remote servers commonly use HTTP or server-sent events (SSE). The language model receives tool descriptions from all connected servers, so a malicious or compromised server can influence decisions involving another server.

The reviewed OWASP material does not publish a quantitative prevalence or breach-rate statistic specific to this Top 10. Treat the categories as a structured risk inventory, not as a ranking by measured incident frequency.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The ten MCP security risks

MCP01:2025 — Token mismanagement and secret exposure

Hard-coded keys, long-lived tokens, secrets retained in model context and unredacted logs can give an attacker direct access and a path to move laterally. Do not place credentials in prompts, tool descriptions, source repositories or persistent conversation memory.

  • Store secrets in a managed vault and inject them only at runtime.
  • Prefer short-lived, narrowly scoped tokens; rotate credentials and revoke them when a job ends.
  • Isolate sensitive context from unrelated agents and redact authorization headers, cookies and personal data in logs.
  • Review model-visible tool output for accidental secret disclosure before it is returned.

MCP02:2025 — Privilege escalation through scope creep

An agent may begin with a temporary permission and gradually acquire broader access, or a tool may request more authority than its task requires. That can let an agent modify repositories, control systems or exfiltrate data.

Apply least privilege per user, agent, server and tool. Set explicit expiry on temporary grants, separate read and write capabilities, require re-authorization for destructive operations and review effective permissions regularly. A permission that is valid for one task should not silently become a standing permission for the next task.

MCP03:2025 — Tool poisoning

A compromised tool, schema or output can manipulate the model. OWASP calls out rug pulls (a trusted tool changes after approval), schema poisoning and tool shadowing, in which a deceptive tool resembles a legitimate one.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Inspect tool names, descriptions, parameter schemas and endpoints before approval.
  • Pin approved definitions and alert on changes; do not automatically trust a newly advertised version.
  • Compare duplicate or similarly named tools and make the intended authority explicit.
  • Scan tool responses for instructions that attempt to override policy or redirect data.

MCP04:2025 — Software supply-chain attacks and dependency tampering

MCP servers often include packages, connectors and transitive dependencies. A malicious update or vulnerable component can introduce a backdoor without changing your application code.

Record provenance for server binaries, packages and container images. Use signed components where available, lock and monitor dependencies, review changes before deployment and keep a software bill of materials. Build and run servers in isolated environments so a compromised dependency cannot reach unrelated files or networks.

MCP05:2025 — Command injection and execution

Untrusted prompt text, retrieved documents or third-party data can reach a shell command, script, API request or code interpreter. Because an agent can assemble arguments dynamically, ordinary input assumptions are unsafe.

  • Validate types, ranges, formats and allowed values at the server boundary.
  • Use parameterized APIs instead of shell concatenation; if a command is unavoidable, use a strict allowlist and safe argument passing.
  • Sandbox execution with separate users, restricted filesystems, disabled privilege escalation and egress controls.
  • Require a human confirmation step for deletion, deployment, money movement or other irreversible actions.

MCP06:2025 — Prompt injection through contextual payloads

Natural-language content can function like an injection string because the model interprets it. Tool descriptions, retrieved pages, documents and tool outputs must therefore be treated as untrusted data, not as policy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep system policy and authorization decisions outside retrieved text. Mark untrusted content clearly, constrain the operations a tool can perform, validate requested destinations and recipients, and ask for confirmation when content attempts to change instructions or disclose data. Output filtering alone is insufficient if the model has already been persuaded to call a dangerous tool.

MCP07:2025 — Insufficient authentication and authorization

Weak identity checks expose multi-user and multi-agent attack paths, particularly for remote HTTP or SSE servers. Authentication proves who is connecting; authorization decides what that identity may do.

  • Use strong authentication, TLS and secure session handling for remote connections.
  • Bind a session and each tool call to the authenticated requester; prevent replay of captured requests.
  • Authorize every sensitive operation server-side, not only in the host interface.
  • Separate tenant data and credentials, and test that one agent cannot invoke another tenant’s tools.

MCP08:2025 — Lack of audit and telemetry

Without reliable records, teams cannot tell which user, agent, server or tool changed context or accessed data. Logs should support detection and forensics without becoming a new secret store.

Capture immutable, time-synchronized events for authentication, tool discovery, schema changes, calls, parameters after redaction, approvals, outputs, context changes, failures and administrative actions. Protect log integrity, restrict access, define retention and alert on unusual destinations, privilege changes, repeated failures and tool-definition drift.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

MCP09:2025 — Shadow MCP servers

Unapproved local or remote servers often run with default credentials, permissive settings or unsecured APIs. They can bypass normal review while still receiving model prompts and data.

  1. Inventory processes, packages, containers, IDE integrations and network endpoints that implement MCP.
  2. Require an owner, documented purpose, approved tools and a security review before connection.
  3. Isolate servers with filesystem, network and identity boundaries; disable unused capabilities.
  4. Continuously monitor for new processes, listening ports, configuration changes and unapproved client connections.

MCP10:2025 — Context injection and over-sharing

Shared or persistent context can expose one task’s, user’s or agent’s sensitive information to another. A tool may also receive more conversation history than it needs.

Scope context to the task and tenant, set explicit retention and deletion rules, pass only the minimum fields required by a tool and prevent automatic carry-over between agents. Test cross-session isolation with synthetic secrets and verify that errors, traces and caches do not reintroduce old context.

Controls to compare before approving an MCP deployment

Evaluate a host, client and server together; a strong server cannot compensate for an over-privileged host.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Control area Questions to answer
Credentials Are tokens short-lived, scoped, injected at runtime, redacted and rotated?
Tool integrity Are schemas pinned, changes detected and similarly named tools distinguished?
Isolation What filesystem, process and network boundaries contain each server?
Human control Which destructive or data-sharing calls require explicit approval?
Validation Are prompt, output, URL, file and SSRF-sensitive inputs validated server-side?
Remote access Are authentication, TLS, requester binding and replay protection enforced?
Supply chain Can you verify provenance, signatures, locked versions and dependency changes?
Telemetry Are calls, context changes and approvals immutably logged with useful alerts?
Governance Can you discover, approve, isolate and monitor every server, including local ones?

A practical hardening procedure

  1. Map the data flow. List users, hosts, clients, servers, tools, credentials, data stores and outbound destinations. Mark every stdio and HTTP/SSE boundary.
  2. Classify actions. Label tools as read-only, mutating or destructive. Set approval requirements and maximum data scope for each class.
  3. Reduce authority. Replace shared administrator credentials with per-task, per-tenant identities and expiring scopes.
  4. Pin and verify. Lock server and dependency versions, record provenance, review tool schemas and detect changes before reconnecting.
  5. Constrain execution. Sandbox processes, deny unnecessary network egress, restrict files and validate all parameters at the server.
  6. Separate trusted policy from content. Treat prompts, documents, tool descriptions and outputs as untrusted; keep authorization logic outside the model’s context.
  7. Instrument and test. Log redacted events, alert on anomalies and run tests for prompt injection, tool shadowing, replay, cross-tenant access and context leakage.
  8. Govern continuously. Reconcile the inventory, review access, rotate credentials and remove servers that no longer have an owner or business need.

Common failure symptoms and fixes

A tool suddenly asks for a new permission

Likely cause: schema drift, a rug pull or scope creep. Fix: block the version, compare the pinned definition with the current one, review the change and issue a narrower, expiring grant only if the change is legitimate.

Logs contain API keys or conversation secrets

Likely cause: request or tool-output logging occurred before redaction. Fix: revoke and rotate exposed credentials, purge copies according to your retention policy, add structured redaction and test logging with canary secrets.

An agent follows instructions inside a web page or document

Likely cause: contextual prompt injection. Fix: label retrieved text untrusted, prevent it from changing system policy, constrain tools and require confirmation for external side effects.

A remote server works for one user but exposes another user’s data

Likely cause: missing requester binding, shared credentials or inadequate tenant authorization. Fix: authenticate each requester, authorize every call server-side, isolate tokens and data stores, and test concurrent sessions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An unknown MCP process appears on a developer workstation

Likely cause: a shadow server installed through an IDE, package or script. Fix: quarantine the process, inventory its files and endpoints, rotate any credentials it accessed, then approve, isolate or remove it through the organization’s MCP registry.

Capturing visual evidence without exposing sensitive context

Security reviews often need screenshots of an approval dialog, tool schema or audit dashboard. Redact secrets before sharing images and avoid sending private prompts to an external capture service. For a controlled, repeatable capture, ScreenshotNeo is a website screenshot API and MCP server. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups and chat widgets; failed loads, bot checks, blank pages, timeouts and cache hits are not billed, and response headers identify the page verdict and billing result.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

One GET request can capture a page for a security record. See the ScreenshotNeo documentation for parameters and authentication.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

The API also supports full-page and element captures, device and viewport settings, dark mode, retina scale, PDF output, custom CSS and JavaScript, clicks, waits, request blocking, headers, cookies, user agents, authorization, timezone and geolocation, transparent backgrounds, resizing, configurable caching, signed image links, asynchronous webhooks, bulk capture of up to 100 URLs per call, a usage API and an OpenAPI specification. An MCP server exposes take_screenshot, get_page_info and capture_pdf to Claude, Cursor and other MCP clients.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Plan Included shots Price
Free 1,000 per month $0, no card
Starter 3,000 $5
Growth 15,000 $15
Pro 60,000 $39
Scale 250,000 $99
Business 1,000,000 $249

Yearly billing gives two months free, and every feature is available on every plan. Start with 1,000 free screenshots a month with no card.

FAQ

Is the MCP Top 10 a certification standard?

No. It is OWASP’s version 0.1 living risk document. Use it to structure threat modeling and controls; it does not certify that a server is secure.

Should every MCP server use OAuth?

The appropriate mechanism depends on the deployment, but remote servers need strong authentication, authorization, TLS, secure sessions and requester binding. Whatever mechanism you choose, keep tokens scoped, short-lived where practical and protected from model context and logs.

Can prompt filtering alone stop MCP attacks?

No. Prompt injection and tool poisoning require defense in depth: least-privilege tools, server-side validation, sandboxing, approval gates, isolation and telemetry.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Frequently Asked Questions

Is the MCP Top 10 a certification standard?

No. It is OWASP’s version 0.1 living risk document. Use it to structure threat modeling and controls; it does not certify that a server is secure.

Should every MCP server use OAuth?

The mechanism depends on deployment, but remote servers need strong authentication, authorization, TLS, secure sessions and requester binding. Keep credentials scoped and protected from model context and logs.

Can prompt filtering alone stop MCP attacks?

No. Combine least privilege, server-side validation, sandboxing, approval gates, isolation and telemetry.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.