OWASP MCP Security Taxonomy

Image for OWASP MCP Security Taxonomy

TL;DR

🚀 What it does: A common, vendor-neutral language for classifying MCP security risks, weaknesses, attack patterns, controls, detections, and test cases.


The OWASP MCP Security Taxonomy provides a common language for securing agentic AI connections, context, and capabilities across the Model Context Protocol ecosystem.

Its complete reference covers MCP trust boundaries, design principles, terminology, common security confusions, risk domains, OWASP MCP Top 10 mappings, CVE-aligned weakness families, controls, detections, test cases, and crosswalks to related security research.

The project is designed for security engineers, developers, GRC teams, and researchers who need a consistent way to describe, assess, and test MCP security.