Open security artifact · MIT + CC BY 4.0

MCP security control matrix

Thirteen controls turn dated MCP requirements and OWASP guidance into tests, review steps, and evidence a release owner can inspect.

This is a review aid, not a certificate. The matrix targets MCP revision 2026-07-28 and cannot replace a threat model or a test against your deployment.

Files

Dated sources

MCP normative levels stay tied to one protocol revision. OWASP rows are marked as guidance instead of borrowed protocol requirements.

Tests, not slogans

Each control includes two concrete procedures and the result a reviewer should expect before release.

Safe evidence names

Evidence fields hold content-free IDs, so a matrix never needs raw tokens, personal data, or private host names.

Verified scope

Deno type checking and eleven validator tests pass without network access or third-party packages. The tests cover duplicate controls, dated MCP sources, OWASP attribution, HTTPS and host restrictions, section links, verification procedures, unknown fields, and content-free evidence IDs.