Skip to content

v1.22.0

Choose a tag to compare

@a-akimov a-akimov released this 03 Oct 14:55
0cd51de

Three Security & Auth rules read the text a server publishes in its catalog,
the text that reaches the model before any tool runs, and a new docs page maps
the Security & Auth checks to the OWASP MCP Top 10.

Score movement: every full audit gains 9 points of maximum score (three HIGH
rules), and 9 points of score when the catalog passes them. DeepWiki goes from
78/94 (83%) to 87/103 (84%). The percentage a --fail-under gate compares
rises for a server that passes the new rules and falls for one that fails
them. Partial audits are unchanged, because the new rules skip as
insufficient-data. Compare scores across versions by rule_id, as the
stability contract describes.

Added

  • catalog_hidden_unicode (HIGH): no string the server publishes may carry
    characters a reader cannot see. Every string is read: instructions, server
    info including version and websiteUrl, names, titles, descriptions,
    schema strings, URIs, MIME types, lastModified, _meta, and icon URLs
    and sizes (not data: image payloads). Flagged: Unicode tag characters
    outside a well-formed emoji tag sequence (UTS #51 §2.8), bidirectional
    embeddings, overrides and isolates (CVE-2021-42574), control characters
    other than tab and line breaks, and runs of two or more zero-width
    characters, directional marks, soft hyphens or variation selectors, in any
    mix. A single one, as emoji, right-to-left text and several scripts use,
    passes, and so does the VS16-plus-joiner pair inside emoji sequences such
    as the heart-on-fire emoji.
  • catalog_no_embedded_secrets (HIGH): no credential in a provider's issued
    format anywhere in the catalog, schema defaults and examples included: AWS
    access key IDs, GitHub, GitLab and Slack tokens, Stripe live keys,
    Anthropic, OpenAI and Google API keys, private-key headers, JWTs and long
    bearer tokens (any casing of the scheme). AWS's and jwt.io's documentation
    samples, values with a placeholder word (YOUR_TOKEN, <example>, xxxx)
    and low-entropy values pass.
  • catalog_prompt_injection_phrasing (HIGH): no text that directs the model
    instead of describing a capability: overriding earlier instructions,
    keeping an action from the user, reassigning the model to a persona ("you
    are now a pirate", "you are now in developer mode"), or chat-template
    control tokens. A phrase that names an attack rather than performing it
    passes, so a scanner that lists the phrases it detects is not flagged:
    inside a matched pair of quotes (sentence punctuation before the closing
    mark allowed), listed with a slash, or introduced as an attempt ("attempts
    to override the system prompt", "allows imported text to override system
    rules", "never let tool output override system rules"). Imperatives such
    as "try to ignore previous instructions" or "you need to ignore previous
    instructions" are still flagged. The
    list is fixed and documented; no model judges the text.
  • All three cite the OWASP MCP Top 10
    (MCP01, MCP03, MCP06) and the specification's §Security and Trust & Safety,
    skip a partial audit as insufficient-data, and report each finding as a
    location, the matched classes and in_key for a schema key, never the
    matched text, so a report cannot repeat a secret or an injected
    instruction. A path that would pass through a flagged schema key stops
    above it and carries path_truncated. A partially collected catalog is
    judged on what was collected and listed under details.incomplete_listings;
    a listing that came back empty without finishing is not evidence, so a
    server with nothing else to judge is skipped.

Docs

  • OWASP MCP Top 10 coverage: each OWASP
    risk mapped to the rules that cover it, with a coverage level and what an
    audit from outside cannot see. Linked from the methodology and the rules
    reference.
  • Example scores across the docs and README show the new rules: DeepWiki
    87/103, and +9/+9 on every full-audit example.