There is no ratified "OWASP MCP Top 10" yet — OWASP's published list is the LLM Top 10, with MCP-specific guidance emerging from its GenAI Security Project. This guide takes the ten MCP risks that show up most in that work and in public scans, and maps each to the four signals TrustedMCP scores: authentication, maintenance, known CVEs, transport safety.

The ten risks

1. Missing or weak authentication

A server with no auth, or one coarse all-scopes token, exposed wider than intended. Roughly 38–40% of public MCP servers run with no authentication. → Authentication signal.

2. Over-scoped credentials

The server authenticates, but the downstream credential (a DB admin URI, a full-access API key) grants far more than the agent needs. → Authentication signal, plus operator configuration.

3. Indirect prompt injection via tool output

A database row, web page, or document returned by a tool carries instructions that the model then acts on. → Not a single signal — mitigate with human-in-the-loop on high-impact tools.

4. Command injection / shell-out on model-controlled input

The server passes model-reachable input to a shell or helper binary. About 43% of tested servers showed a command-injection weakness. → Transport safety signal.

5. Insecure transport

Plaintext stdio between hosts, or HTTP without enforced TLS. stdio also carries no identity and runs with your full user permissions. → Transport safety signal.

6. Token and secret exposure

API keys committed in mcp.json, printed to logs, or captured in a model transcript. → Authentication signal — prefer OAuth with short-lived tokens.

7. Supply-chain risk

An unvetted npx -y <package> pulls a typosquat or a compromised dependency at run time. → Maintenance signal, plus pin the exact version.

8. Unpatched vulnerabilities and stale maintenance

An open advisory with no fix, or a server with no meaningful commit in months so a fix is unlikely to land. → Known CVEs and maintenance signals.

9. Tool poisoning and rug-pulls

A server changes a tool's behaviour or description after you trust it — a new maintainer, a malicious update. → Maintenance signal — re-review on every version bump.

10. No confirmation on high-impact actions

Payments, writes, deploys, and bulk edits fire automatically off tool output with no human in the loop. → Operator responsibility — gate them explicitly.

How to use this

Risks 1, 4, 5, 6, 7, 8, and 9 are visible in public data, which is why the TrustedMCP score weights authentication, maintenance, CVEs, and transport. Risks 2, 3, and 10 are decisions you make when you deploy a server — the MCP security best practices checklist covers those. Check a server's grade in the directory before you enable it, then harden your own configuration on top.

Need this built and hardened for you?

We build custom, security-reviewed MCP servers. Tell us what you need an agent to reach.

Start a conversation