owasp-mcpbởi microsoft
OWASP MCP Top 10 vulnerability knowledge base for identifying, assessing, and remediating security risks in Model Context Protocol environments - Brought to…
npx skills add https://github.com/microsoft/hve-core --skill owasp-mcpOWASP MCP Top 10 — Skill Entry
This SKILL.md is the entrypoint for the MCP Vulnerabilities skill.
The skill encodes the OWASP MCP Top 10 (2025) as structured, machine-readable references that an agent can query to identify, assess, and remediate MCP security risks.
Normative references (MCP Top 10)
- 00 Vulnerability Index
- 01 Token Mismanagement and Secret Exposure
- 02 Privilege Escalation via Scope Creep
- 03 Tool Poisoning
- 04 Software Supply Chain Attacks and Dependency Tampering
- 05 Command Injection and Execution
- 06 Prompt Injection via Contextual Payloads
- 07 Insufficient Authentication and Authorization
- 08 Lack of Audit and Telemetry
- 09 Shadow MCP Servers
- 10 Context Injection and Over-Sharing
Skill layout
SKILL.md— this file (skill entrypoint).references/— the MCP Top 10 normative documents.00-vulnerability-index.md— index of all vulnerability identifiers, severities, and cross-references.01through10— one document per vulnerability aligned with OWASP MCP numbering.
🤖 Crafted with precision by ✨Copilot following brilliant human instruction, then carefully refined by our team of discerning human reviewers.
Thêm skills từ microsoft
oss-growth
by microsoft
OSS growth hacker persona
pr-description-skill
by microsoft
Trigger this skill on any of the following intents:
python-architecture
by microsoft
Python architect persona
supply-chain-security
by microsoft
Supply chain security expert persona
skill-name
by microsoft
Description of what the skill does and when to use it
work-iterations
by microsoft
List, create, and assign iterations for Azure DevOps projects and teams.
django
by microsoft
Best practices for Django web development including models, views, templates, and testing.
flask
by microsoft
Best practices for Flask web development including routing, blueprints, and testing.