Open security artifact · MIT + CC BY 4.0
MCP security control matrix
Thirteen controls turn dated MCP requirements and OWASP guidance into tests, review steps, and evidence a release owner can inspect.
Files
Dated sources
MCP normative levels stay tied to one protocol revision. OWASP rows are marked as guidance instead of borrowed protocol requirements.
Tests, not slogans
Each control includes two concrete procedures and the result a reviewer should expect before release.
Safe evidence names
Evidence fields hold content-free IDs, so a matrix never needs raw tokens, personal data, or private host names.
Verified scope
Deno type checking and eleven validator tests pass without network access or third-party packages. The tests cover duplicate controls, dated MCP sources, OWASP attribution, HTTPS and host restrictions, section links, verification procedures, unknown fields, and content-free evidence IDs.