Repository navigation
v1.22.0
Three Security & Auth rules read the text a server publishes in its catalog,
the text that reaches the model before any tool runs, and a new docs page maps
the Security & Auth checks to the OWASP MCP Top 10.
Score movement: every full audit gains 9 points of maximum score (three HIGH
rules), and 9 points of score when the catalog passes them. DeepWiki goes from
78/94 (83%) to 87/103 (84%). The percentage a --fail-under gate compares
rises for a server that passes the new rules and falls for one that fails
them. Partial audits are unchanged, because the new rules skip as
insufficient-data. Compare scores across versions by rule_id, as the
stability contract describes.
Added
catalog_hidden_unicode(HIGH): no string the server publishes may carry
characters a reader cannot see. Every string is read: instructions, server
info including version andwebsiteUrl, names, titles, descriptions,
schema strings, URIs, MIME types,lastModified,_meta, and icon URLs
and sizes (notdata:image payloads). Flagged: Unicode tag characters
outside a well-formed emoji tag sequence (UTS #51 §2.8), bidirectional
embeddings, overrides and isolates (CVE-2021-42574), control characters
other than tab and line breaks, and runs of two or more zero-width
characters, directional marks, soft hyphens or variation selectors, in any
mix. A single one, as emoji, right-to-left text and several scripts use,
passes, and so does the VS16-plus-joiner pair inside emoji sequences such
as the heart-on-fire emoji.catalog_no_embedded_secrets(HIGH): no credential in a provider's issued
format anywhere in the catalog, schema defaults and examples included: AWS
access key IDs, GitHub, GitLab and Slack tokens, Stripe live keys,
Anthropic, OpenAI and Google API keys, private-key headers, JWTs and long
bearer tokens (any casing of the scheme). AWS's and jwt.io's documentation
samples, values with a placeholder word (YOUR_TOKEN,<example>,xxxx)
and low-entropy values pass.catalog_prompt_injection_phrasing(HIGH): no text that directs the model
instead of describing a capability: overriding earlier instructions,
keeping an action from the user, reassigning the model to a persona ("you
are now a pirate", "you are now in developer mode"), or chat-template
control tokens. A phrase that names an attack rather than performing it
passes, so a scanner that lists the phrases it detects is not flagged:
inside a matched pair of quotes (sentence punctuation before the closing
mark allowed), listed with a slash, or introduced as an attempt ("attempts
to override the system prompt", "allows imported text to override system
rules", "never let tool output override system rules"). Imperatives such
as "try to ignore previous instructions" or "you need to ignore previous
instructions" are still flagged. The
list is fixed and documented; no model judges the text.- All three cite the OWASP MCP Top 10
(MCP01, MCP03, MCP06) and the specification's §Security and Trust & Safety,
skip a partial audit asinsufficient-data, and report each finding as a
location, the matched classes andin_keyfor a schema key, never the
matched text, so a report cannot repeat a secret or an injected
instruction. A path that would pass through a flagged schema key stops
above it and carriespath_truncated. A partially collected catalog is
judged on what was collected and listed underdetails.incomplete_listings;
a listing that came back empty without finishing is not evidence, so a
server with nothing else to judge is skipped.
Docs
- OWASP MCP Top 10 coverage: each OWASP
risk mapped to the rules that cover it, with a coverage level and what an
audit from outside cannot see. Linked from the methodology and the rules
reference. - Example scores across the docs and README show the new rules: DeepWiki
87/103, and +9/+9 on every full-audit example.